Open Vulnerability and Assessment Language (OVAL)
Offical Language Release Repository Downloads News — November 5, 2009 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:100117 Date: 2005-08-16
Title: libtiff Directory Entry Count Integer Overflow Vulnerability
Description: Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.
Version: 1 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2004-1308
Family: unix
Platform(s): Sun Solaris 7
Sun Solaris 8
Sun Solaris 9
Sun Solaris 10
Product(s): libtiff
Definition Synopsis: