CVE-2004-1183: Integer Overflow
Published Jan 6, 2005
·Updated
Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.
Affected Software
12 affected components
LibTIFF libtiff=3.4
LibTIFF libtiff=3.5.1
LibTIFF libtiff=3.5.2
LibTIFF libtiff=3.5.3
LibTIFF libtiff=3.5.4
LibTIFF libtiff=3.5.5
LibTIFF libtiff=3.5.6
LibTIFF libtiff=3.5.7
LibTIFF libtiff=3.6.0
LibTIFF libtiff=3.6.1
LibTIFF libtiff=3.7.0
LibTIFF libtiff=3.7.1
Remediation
Patch Available
Event History
Jan 6, 2005
CVE Published
05:00 AM
Jan 19, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1183?
CVE-2004-1183 is classified as a medium severity vulnerability due to its potential for causing a denial of service and possible remote code execution.
2
How do I fix CVE-2004-1183?
To address CVE-2004-1183, upgrade to a patched version of libtiff that is later than 3.7.1, ensuring the software is no longer vulnerable.
3
What systems are affected by CVE-2004-1183?
CVE-2004-1183 affects libtiff versions 3.4 through 3.7.1.
4
What type of vulnerability is CVE-2004-1183?
CVE-2004-1183 is an integer overflow vulnerability in the tiffdump utility for libtiff.
5
Can CVE-2004-1183 lead to remote code execution?
Yes, CVE-2004-1183 may allow remote attackers to execute arbitrary code via crafted TIFF files.