imPC@ndo EN

Tracker / CVE-2004-1307

CVE-2004-1307

Alta 7.5

Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.

Prodotti e versioni affette

apple mac_os_x
apple mac_os_x_server
avaya call_management_system_server
avaya cvlan
avaya integrated_management
avaya interactive_response
avaya intuity_audix_lx
avaya mn100
avaya modular_messaging_message_storage_server
conectiva linux
f5 icontrol_service_manager
gentoo linux
libtiff libtiff
mandrakesoft mandrake_linux
mandrakesoft mandrake_linux_corporate_server
sco unixware
sgi propack
sun solaris
sun sunos

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti