CVE Vulnerabilities

CVE-2004-1308

Published: Jan 10, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
LibtiffLibtiff3.4 (including)3.4 (including)
LibtiffLibtiff3.5.1 (including)3.5.1 (including)
LibtiffLibtiff3.5.2 (including)3.5.2 (including)
LibtiffLibtiff3.5.3 (including)3.5.3 (including)
LibtiffLibtiff3.5.4 (including)3.5.4 (including)
LibtiffLibtiff3.5.5 (including)3.5.5 (including)
LibtiffLibtiff3.5.7 (including)3.5.7 (including)
LibtiffLibtiff3.6.0 (including)3.6.0 (including)
LibtiffLibtiff3.6.1 (including)3.6.1 (including)
LibtiffLibtiff3.7.0 (including)3.7.0 (including)
Red Hat Enterprise Linux 3RedHatlibtiff-0:3.5.7-22.el3*
Red Hat Enterprise Linux 3RedHatkdegraphics-7:3.1.3-3.7*
Red Hat Enterprise Linux 4RedHatlibtiff-0:3.6.1-8*
TiffUbuntudapper*
TiffUbuntudevel*
TiffUbuntuedgy*
TiffUbuntufeisty*

References