CVE-2004-1307
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
Published:Dec 21, 2004
Last Modified:Apr 16, 2026
EPS:May 4, 2005
EPSS Score:0.05111
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Apple
Product
Mac Os X
Apple
Mac Os X
Vendor
Apple
Product
Mac Os X Server
Apple
Mac Os X Server
Vendor
Avaya
Product
Call Management System Server
Avaya
Call Management System Server
Vendor
Avaya
Product
Cvlan
Avaya
Cvlan
Vendor
Avaya
Product
Integrated Management
Avaya
Integrated Management
Vendor
Avaya
Product
Interactive Response
Avaya
Interactive Response
Vendor
Avaya
Product
Intuity Audix Lx
Avaya
Intuity Audix Lx
Vendor
Avaya
Product
Mn100
Avaya
Mn100
Vendor
Avaya
Product
Modular Messaging Message Storage Server
Avaya
Modular Messaging Message Storage Server
Vendor
Conectiva
Product
Linux
Conectiva
Linux
Vendor
F5
Product
Icontrol Service Manager
F5
Icontrol Service Manager
Vendor
Gentoo
Product
Linux
Gentoo
Linux
Vendor
Libtiff
Product
Libtiff
Libtiff
Libtiff
Vendor
Mandrakesoft
Product
Mandrake Linux
Mandrakesoft
Mandrake Linux
Vendor
Mandrakesoft
Product
Mandrake Linux Corporate Server
Mandrakesoft
Mandrake Linux Corporate Server
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Sco
Product
Unixware
Sco
Unixware
Vendor
Sgi
Product
Propack
Sgi
Propack
Vendor
Sun
Product
Solaris
Sun
Solaris
Vendor
Sun
Product
Sunos
Sun
Sunos
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
