Vulnerability Details CVE-2004-1307
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.051
EPSS Ranking 89.3%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2004-1307
-
cpe:2.3:a:avaya:call_management_system_server:11.0
-
cpe:2.3:a:avaya:call_management_system_server:12.0
-
cpe:2.3:a:avaya:call_management_system_server:13.0
-
cpe:2.3:a:avaya:call_management_system_server:8.0
-
cpe:2.3:a:avaya:call_management_system_server:9.0
-
-
cpe:2.3:a:avaya:integrated_management:-
-
cpe:2.3:a:avaya:interactive_response:-
-
cpe:2.3:a:avaya:interactive_response:1.2.1
-
cpe:2.3:a:avaya:interactive_response:1.3
-
cpe:2.3:a:avaya:intuity_audix_lx:-
-
cpe:2.3:a:avaya:intuity_audix_lx:2.0
-
-
cpe:2.3:a:f5:icontrol_service_manager:1.3
-
cpe:2.3:a:f5:icontrol_service_manager:1.3.4
-
cpe:2.3:a:f5:icontrol_service_manager:1.3.5
-
cpe:2.3:a:f5:icontrol_service_manager:1.3.6
-
cpe:2.3:a:libtiff:libtiff:3.4
-
cpe:2.3:a:libtiff:libtiff:3.5.1
-
cpe:2.3:a:libtiff:libtiff:3.5.2
-
cpe:2.3:a:libtiff:libtiff:3.5.3
-
cpe:2.3:a:libtiff:libtiff:3.5.4
-
cpe:2.3:a:libtiff:libtiff:3.5.5
-
cpe:2.3:a:libtiff:libtiff:3.5.7
-
cpe:2.3:a:libtiff:libtiff:3.6.0
-
cpe:2.3:a:libtiff:libtiff:3.6.1
-
cpe:2.3:a:libtiff:libtiff:3.7.0
-
cpe:2.3:a:sgi:propack:3.0
-
cpe:2.3:o:apple:mac_os_x:10.3
-
cpe:2.3:o:apple:mac_os_x:10.3.1
-
cpe:2.3:o:apple:mac_os_x:10.3.2
-
cpe:2.3:o:apple:mac_os_x:10.3.3
-
cpe:2.3:o:apple:mac_os_x:10.3.4
-
cpe:2.3:o:apple:mac_os_x:10.3.5
-
cpe:2.3:o:apple:mac_os_x:10.3.6
-
cpe:2.3:o:apple:mac_os_x:10.3.7
-
cpe:2.3:o:apple:mac_os_x:10.3.8
-
cpe:2.3:o:apple:mac_os_x:10.3.9
-
cpe:2.3:o:apple:mac_os_x_server:10.3
-
cpe:2.3:o:apple:mac_os_x_server:10.3.1
-
cpe:2.3:o:apple:mac_os_x_server:10.3.2
-
cpe:2.3:o:apple:mac_os_x_server:10.3.3
-
cpe:2.3:o:apple:mac_os_x_server:10.3.4
-
cpe:2.3:o:apple:mac_os_x_server:10.3.5
-
cpe:2.3:o:apple:mac_os_x_server:10.3.6
-
cpe:2.3:o:apple:mac_os_x_server:10.3.7
-
cpe:2.3:o:apple:mac_os_x_server:10.3.8
-
cpe:2.3:o:apple:mac_os_x_server:10.3.9
-
cpe:2.3:o:avaya:modular_messaging_message_storage_server:1.1
-
cpe:2.3:o:avaya:modular_messaging_message_storage_server:2.0
-
cpe:2.3:o:conectiva:linux:10.0
-
cpe:2.3:o:conectiva:linux:9.0
-
-
cpe:2.3:o:gentoo:linux:1.2
-
cpe:2.3:o:gentoo:linux:1.4
-
cpe:2.3:o:gentoo:linux:2.1.30
-
cpe:2.3:o:gentoo:linux:2.2.28
-
cpe:2.3:o:gentoo:linux:2.3.30
-
cpe:2.3:o:mandrakesoft:mandrake_linux:10.0
-
cpe:2.3:o:mandrakesoft:mandrake_linux:10.1
-
cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:3.0
-
cpe:2.3:o:sco:unixware:7.1.4
-
cpe:2.3:o:sun:solaris:10.0
-
cpe:2.3:o:sun:solaris:7.0
-
cpe:2.3:o:sun:solaris:8.0
-
cpe:2.3:o:sun:solaris:9.0
-
-