LibTIFF OJPEG Heap Buffer Overflow Vulnerability
BID:11506
Info
LibTIFF OJPEG Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 11506 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0929 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Andrei Nigmatulin discovered this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 SuSE Linux 8.1 SCO Unixware 7.1.4 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 LibTIFF LibTIFF 3.6.1 |
| Not Vulnerable: | |
Discussion
LibTIFF OJPEG Heap Buffer Overflow Vulnerability
LibTIFF is affected by a heap buffer overflow vulnerability. This issue is due to a failure of the application to properly perform boundary checks prior to copying user-supplied strings into finite process buffers.
An attacker may leverage this issue to execute arbitrary code on a vulnerable computer with the privileges of the user running the vulnerable application, facilitating unauthorized access. This issue may also be leveraged to cause an affected application to crash.
LibTIFF is affected by a heap buffer overflow vulnerability. This issue is due to a failure of the application to properly perform boundary checks prior to copying user-supplied strings into finite process buffers.
An attacker may leverage this issue to execute arbitrary code on a vulnerable computer with the privileges of the user running the vulnerable application, facilitating unauthorized access. This issue may also be leveraged to cause an affected application to crash.
Exploit / POC
LibTIFF OJPEG Heap Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
LibTIFF OJPEG Heap Buffer Overflow Vulnerability
Solution:
SCO has released an advisory (SCOSA-2005.19) and fixes to address this issue for UnixWare platforms. Please see the referenced advisory for further information.
SuSE Linux has released advisory SUSE-SA:2004:038 along with fixes to address this issue. Please see the referenced advisory for further information.
LibTIFF LibTIFF 3.6.1
SCO Unixware 7.1.4
Solution:
SCO has released an advisory (SCOSA-2005.19) and fixes to address this issue for UnixWare platforms. Please see the referenced advisory for further information.
SuSE Linux has released advisory SUSE-SA:2004:038 along with fixes to address this issue. Please see the referenced advisory for further information.
LibTIFF LibTIFF 3.6.1
-
SuSE libtiff-3.6.1-38.12.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/libtiff-3.6.1-38. 12.i586.patch.rpm -
SuSE libtiff-3.6.1-38.12.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/libtiff-3.6.1-38. 12.i586.rpm
SCO Unixware 7.1.4
-
SCO SCOSA-2005.19
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.19
References
LibTIFF OJPEG Heap Buffer Overflow Vulnerability
References:
References:
- LibTIFF Homepage (LibTIFF)
- iDEFENSE Security Advisory XX.XX.04 - Novell SuSe Linux LibTIFF Heap Overflow Vu ("customer service mailbox"
)