Integer Overflow Vulnerability in libtiff Affects Multiple Platforms
CVE-2004-1307

Currently unrated

Key Information:

Vendor
Avaya
Vendor
CVE Published:
21 December 2004

Summary

The vulnerability arises from an integer overflow in the TIFFFetchStripThing function found within tif_dirread.c in libtiff version 3.6.1. This issue allows potential attackers to execute arbitrary code by providing a specially crafted TIFF file that includes the STRIPOFFSETS flag alongside a significant number of strips. The vulnerability can lead to a heap-based buffer overflow, which can compromise system integrity and security, enabling unauthorized access or control.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.