First published: Tue Dec 21 2004(Updated: )
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avaya Interactive Response | =1.2.1 | |
libtiff | =3.6.1 | |
Conectiva Linux | =9.0 | |
SGI ProPack | =3.0 | |
Avaya Call Management System Server | =8.0 | |
F5 iControl Service Manager | =1.3.5 | |
Avaya Integrated Management Suite | ||
Avaya Interactive Response | =1.3 | |
Avaya Call Management System Server | =13.0 | |
libtiff | =3.4 | |
F5 iControl Service Manager | =1.3.4 | |
libtiff | =3.5.7 | |
libtiff | =3.7.0 | |
Avaya Intuity Audix LX | ||
libtiff | =3.6.0 | |
libtiff | =3.5.3 | |
libtiff | =3.5.4 | |
libtiff | =3.5.2 | |
Avaya Call Management System Server | =9.0 | |
Avaya CVLAN | ||
Avaya Interactive Response | ||
libtiff | =3.5.5 | |
Conectiva Linux | =10.0 | |
libtiff | =3.5.1 | |
Avaya Call Management System Server | =11.0 | |
F5 iControl Service Manager | =1.3.6 | |
F5 iControl Service Manager | =1.3 | |
Avaya Call Management System Server | =12.0 | |
Apple macOS Server | =10.3.2 | |
Xinuos UnixWare | =7.1.4 | |
Apple macOS Server | =10.3.7 | |
Apple macOS Server | =10.3.5 | |
Apple iOS and macOS | =10.3.1 | |
Apple iOS and macOS | =10.3.5 | |
Apple macOS Server | =10.3.3 | |
Avaya Modular Messaging Message Storage Server | =2.0 | |
Mandrake Linux | =10.1 | |
Sun SunOS | =5.7 | |
Sun SunOS | =5.8 | |
Apple macOS Server | =10.3.4 | |
Avaya MN100 | ||
Oracle Solaris SPARC | =9.0 | |
Apple iOS and macOS | =10.3.2 | |
Oracle Solaris SPARC | =10.0 | |
Apple iOS and macOS | =10.3.7 | |
Mandriva Linux Corporate Server | =3.0 | |
Oracle Solaris SPARC | =7.0 | |
Mandriva Linux Corporate Server | =3.0 | |
Apple iOS and macOS | =10.3.6 | |
Apple macOS Server | =10.3 | |
Apple macOS Server | =10.3.8 | |
Apple macOS Server | =10.3.9 | |
Oracle Solaris SPARC | =9.0 | |
Apple iOS and macOS | =10.3.8 | |
Apple macOS Server | =10.3.1 | |
Mandrake Linux | =10.0 | |
Apple iOS and macOS | =10.3.9 | |
Apple iOS and macOS | =10.3.4 | |
Apple iOS and macOS | =10.3.3 | |
Avaya Modular Messaging Message Storage Server | =1.1 | |
Oracle Solaris SPARC | =9.0-x86_update_2 | |
Gentoo Linux | ||
Oracle Solaris SPARC | =8.0 | |
Apple iOS and macOS | =10.3 | |
Apple macOS Server | =10.3.6 | |
Mandrake Linux | =10.0 | |
Mandrake Linux | =10.1 | |
Oracle Solaris SPARC | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1307 is considered a high severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2004-1307, update the affected libtiff library to a version that addresses this vulnerability.
CVE-2004-1307 is caused by an integer overflow in the TIFFFetchStripThing function in libtiff, which leads to a heap-based buffer overflow.
CVE-2004-1307 affects libtiff version 3.6.1 and various other software that relies on this library, including certain Avaya and F5 products.
Yes, CVE-2004-1307 can be exploited remotely via specially crafted TIFF files.