First published: Tue Oct 26 2004(Updated: )
Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support) option, allows remote attackers to execute arbitrary code via a malformed TIFF image.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIFF | =3.6.1 | |
SUSE Linux | =1.0 | |
SUSE Linux | =8 | |
SUSE Linux | =8.1 | |
SUSE Linux | =8.2 | |
SUSE Linux | =9.0 | |
SUSE Linux | =9.0 | |
SUSE Linux | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0929 has a high severity rating due to the potential for remote code execution.
To fix CVE-2004-0929, you should update libtiff to a version later than 3.6.1 that does not include OJPEG_SUPPORT.
CVE-2004-0929 affects libtiff version 3.6.1 and earlier, particularly in certain versions of SUSE Linux.
Yes, CVE-2004-0929 can be exploited remotely through the use of a malformed TIFF image.
The consequences of CVE-2004-0929 include potential arbitrary code execution, leading to system compromise.