LibTIFF TIFFFindFieldInfo Remote Buffer Overflow Vulnerability
BID:19793
Info
LibTIFF TIFFFindFieldInfo Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 19793 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 31 2006 12:00AM |
| Updated: | Oct 25 2007 12:17AM |
| Credit: | NOPx86 discovered this issue. |
| Vulnerable: |
Sony PSP 2.0 firmware Sony PSP 2.8 firmware Sony PSP 2.7 firmware Sony PSP 2.6 firmware LibTIFF LibTIFF 3.8.2 LibTIFF LibTIFF 3.8.1 LibTIFF LibTIFF 3.8 LibTIFF LibTIFF 3.7.3 LibTIFF LibTIFF 3.7.2 LibTIFF LibTIFF 3.7.1 LibTIFF LibTIFF 3.7 LibTIFF LibTIFF 3.6.1 LibTIFF LibTIFF 3.6 .0 LibTIFF LibTIFF 3.5.7 LibTIFF LibTIFF 3.5.5 LibTIFF LibTIFF 3.5.4 LibTIFF LibTIFF 3.5.3 LibTIFF LibTIFF 3.5.2 LibTIFF LibTIFF 3.5.1 LibTIFF LibTIFF 3.4 Apple iPod Touch 0 Apple iPhone 1.1.1 |
| Not Vulnerable: | |
Discussion
LibTIFF TIFFFindFieldInfo Remote Buffer Overflow Vulnerability
LibTIFF is prone to a buffer-overflow vulnerability because the library fails to do proper boundary checks before copying user-supplied data into a finite-sized buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of appications using the affected library. Failed exploit attempts will likely crash the application, denying service to legitimate users.
This issue is known to affect versions of LibTIFF included with Sony PSP devices running firmware versions 2.0 through 2.8.
Specific information regarding affected versions of LibTIFF is currently unavailable. We will update this BID as more information emerges.
LibTIFF is prone to a buffer-overflow vulnerability because the library fails to do proper boundary checks before copying user-supplied data into a finite-sized buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of appications using the affected library. Failed exploit attempts will likely crash the application, denying service to legitimate users.
This issue is known to affect versions of LibTIFF included with Sony PSP devices running firmware versions 2.0 through 2.8.
Specific information regarding affected versions of LibTIFF is currently unavailable. We will update this BID as more information emerges.
Exploit / POC
LibTIFF TIFFFindFieldInfo Remote Buffer Overflow Vulnerability
The following exploits are available:
UPDATE (October 11, 2007): An exploit for Apple iPhone and iPod Touch devices is available. Please see the references for more information.
The following exploits are available:
UPDATE (October 11, 2007): An exploit for Apple iPhone and iPod Touch devices is available. Please see the references for more information.
Solution / Fix
LibTIFF TIFFFindFieldInfo Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any official vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any official vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
LibTIFF TIFFFindFieldInfo Remote Buffer Overflow Vulnerability
References:
References:
- A new exploit discovered, might help in cracking 1.1.1 soon (Hackintosh)
- Cracking the iPhone (part 2.1) (hdm)
- Hello World Application for 2.0-2.80 PSP's (QJ.Net)
- Libtiff Exploit for 2.80 And Lower. No Joke. Real. (NOPx86)
- LibTIFF Homepage (LibTIFF)
- The iPhone / iTouch tif exploit is now officially released! (Toc2rta)
- Cracking the iPhone (5 article series) (H D Moore
) - Cracking the iPhone (part 2) (hdm)