CVE Vulnerabilities

CVE-2004-1307

Published: Dec 21, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
Call_management_system_serverAvaya8.0 (including)8.0 (including)
Call_management_system_serverAvaya9.0 (including)9.0 (including)
Call_management_system_serverAvaya11.0 (including)11.0 (including)
Call_management_system_serverAvaya12.0 (including)12.0 (including)
Call_management_system_serverAvaya13.0 (including)13.0 (including)
CvlanAvaya**
Integrated_managementAvaya**
Interactive_responseAvaya**
Interactive_responseAvaya1.2.1 (including)1.2.1 (including)
Interactive_responseAvaya1.3 (including)1.3 (including)
Intuity_audix_lxAvaya**
Icontrol_service_managerF51.3 (including)1.3 (including)
Icontrol_service_managerF51.3.4 (including)1.3.4 (including)
Icontrol_service_managerF51.3.5 (including)1.3.5 (including)
Icontrol_service_managerF51.3.6 (including)1.3.6 (including)
LibtiffLibtiff3.4 (including)3.4 (including)
LibtiffLibtiff3.5.1 (including)3.5.1 (including)
LibtiffLibtiff3.5.2 (including)3.5.2 (including)
LibtiffLibtiff3.5.3 (including)3.5.3 (including)
LibtiffLibtiff3.5.4 (including)3.5.4 (including)
LibtiffLibtiff3.5.5 (including)3.5.5 (including)
LibtiffLibtiff3.5.7 (including)3.5.7 (including)
LibtiffLibtiff3.6.0 (including)3.6.0 (including)
LibtiffLibtiff3.6.1 (including)3.6.1 (including)
LibtiffLibtiff3.7.0 (including)3.7.0 (including)
PropackSgi3.0 (including)3.0 (including)
LinuxConectiva9.0 (including)9.0 (including)
LinuxConectiva10.0 (including)10.0 (including)
Red Hat Enterprise Linux 3RedHatlibtiff-0:3.5.7-20.1*
Red Hat Enterprise Linux 3RedHatkdegraphics-7:3.1.3-3.7*

References