CVE-2004-1307: Buffer Overflow
Integer overflow in the TIFFFetchStripThing function in tifdirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1307?
CVE-2004-1307 is considered a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2004-1307?
To fix CVE-2004-1307, update the affected libtiff library to a version that addresses this vulnerability.
What causes CVE-2004-1307?
CVE-2004-1307 is caused by an integer overflow in the TIFFFetchStripThing function in libtiff, which leads to a heap-based buffer overflow.
Which software is affected by CVE-2004-1307?
CVE-2004-1307 affects libtiff version 3.6.1 and various other software that relies on this library, including certain Avaya and F5 products.
Can CVE-2004-1307 be exploited remotely?
Yes, CVE-2004-1307 can be exploited remotely via specially crafted TIFF files.