CVE-2004-0886: Integer Overflow
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0886?
CVE-2004-0886 has a severity rating that could lead to denial of service through crashes or memory corruption.
How do I fix CVE-2004-0886?
To fix CVE-2004-0886, upgrade to versions of libtiff later than 3.6.1 that have patched the integer overflow vulnerabilities.
What systems are affected by CVE-2004-0886?
CVE-2004-0886 affects libtiff versions 3.6.1 and earlier as well as several applications using vulnerable versions of libtiff.
How can CVE-2004-0886 be exploited?
CVE-2004-0886 can be exploited by remote attackers through specially crafted TIFF images that trigger integer overflows.
Is there a known workaround for CVE-2004-0886?
There are no known effective workarounds for CVE-2004-0886, and users are advised to apply available updates.