CVE-2005-1544: Buffer Overflow
Published May 14, 2005
·Updated
Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.
Affected Software
12 affected components
LibTIFF libtiff=3.4
LibTIFF libtiff=3.5.1
LibTIFF libtiff=3.5.2
LibTIFF libtiff=3.5.3
LibTIFF libtiff=3.5.4
LibTIFF libtiff=3.5.5
LibTIFF libtiff=3.5.6
LibTIFF libtiff=3.5.7
LibTIFF libtiff=3.6.0
LibTIFF libtiff=3.6.1
LibTIFF libtiff=3.7.0
LibTIFF libtiff=3.7.1
Remediation
Patch Available
Event History
May 14, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1544?
CVE-2005-1544 has a high severity level due to its potential to allow remote code execution.
2
How do I fix CVE-2005-1544?
To fix CVE-2005-1544, upgrade to libTIFF version 3.7.2 or later.
3
Which versions of libTIFF are affected by CVE-2005-1544?
CVE-2005-1544 affects libTIFF versions 3.4 through 3.7.1.
4
What type of vulnerability is CVE-2005-1544?
CVE-2005-1544 is a stack-based buffer overflow vulnerability.
5
Can CVE-2005-1544 be exploited remotely?
Yes, CVE-2005-1544 can be exploited remotely through a specially crafted TIFF file.