Description
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
References (7)
Core 7
Core References
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA05-136A.html
Patch, Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/539110
Vendor Advisory vendor-advisory
x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201072-1
Vendor Advisory vendor-advisory
x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1
Patch, Vendor Advisory third-party-advisory
x_refsource_idefense
http://www.idefense.com/application/poi/display?id=173&type=vulnerabilities&flashstatus=true
Patch, Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2005/May/msg00001.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11175
Scores
EPSS
0.0511
EPSS Percentile
89.9%
Details
Status
published
Products (50)
apple/mac_os_x
10.3
apple/mac_os_x
10.3.1
apple/mac_os_x
10.3.2
apple/mac_os_x
10.3.3
apple/mac_os_x
10.3.4
apple/mac_os_x
10.3.5
apple/mac_os_x
10.3.6
apple/mac_os_x
10.3.7
apple/mac_os_x
10.3.8
apple/mac_os_x
10.3.9
... and 40 more
Published
Dec 21, 2004
Tracked Since
Feb 18, 2026