LibTIFF Integer Overflows Let Remote Users Crash the Application
|
|
SecurityTracker Alert ID: 1011674 |
|
SecurityTracker URL: http://securitytracker.com/id/1011674
|
|
CVE Reference:
CVE-2004-0886
(Links to External Site)
|
Updated: May 5 2009
|
Original Entry Date: Oct 14 2004
|
Impact:
Denial of service via network
|
|
|
Description:
Some vulnerabilities were reported in LibTIFF. A remote user can cause an application using LibTIFF to crash.
Red Hat reported that a remote user can create a specially crafted image file that, when loaded by the target user, will trigger an integer overflow and cause LibTIFF to crash.
Dimitry Levin is credited with reporting this flaw.
|
Impact:
A remote user can cause the target application to crash.
|
Solution:
No upstream solution was available at the time of this entry.
Red Hat will be issuing fixes in 3.5.5-17 (RHEL2.1) and 3.5.7-20.1 (RHEL3).
|
Vendor URL: www.libtiff.org/ (Links to External Site)
|
Cause:
Boundary error
|
Underlying OS:
Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Thu, 14 Oct 2004 01:42:38 -0400
Subject: [none]
|
CVE: CAN-2004-0886
Red Hat reported that there are several integer overflows in LibTIFF. A specially
crafted image file could cause LibTIFF to crash.
Dimitry Levin is credited with reporting this flaw.
|
|