Description
Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-46-1 | TIFF library vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T00:46:12.421Z
Reserved: 2004-12-21T00:00:00.000Z
Link: CVE-2004-1308
No data.
Status : Modified
Published: 2005-01-10T05:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2004-1308
OpenCVE Enrichment
No data.
Weaknesses
Ubuntu USN