Unknown
CVE-2004-1307
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- call management system server 11.0,
- call management system server 12.0,
- call management system server 13.0,
- call management system server 8.0,
- call management system server 9.0,
- cvlan,
- icontrol service manager 1.3,
- icontrol service manager 1.3.4,
- icontrol service manager 1.3.5,
- icontrol service manager 1.3.6,
- integrated management,
- interactive response,
- interactive response 1.2.1,
- interactive response 1.3,
- intuity audix lx,
- libtiff 3.4,
- libtiff 3.5.1,
- libtiff 3.5.2,
- libtiff 3.5.3,
- libtiff 3.5.4,
- libtiff 3.5.5,
- libtiff 3.5.7,
- libtiff 3.6.0,
- libtiff 3.6.1,
- libtiff 3.7.0,
- linux,
- linux 10.0,
- linux 9.0,
- mac os x 10.3,
- mac os x 10.3.1,
- mac os x 10.3.2,
- mac os x 10.3.3,
- mac os x 10.3.4,
- mac os x 10.3.5,
- mac os x 10.3.6,
- mac os x 10.3.7,
- mac os x 10.3.8,
- mac os x 10.3.9,
- mac os x server 10.3,
- mac os x server 10.3.1,
- mac os x server 10.3.2,
- mac os x server 10.3.3,
- mac os x server 10.3.4,
- mac os x server 10.3.5,
- mac os x server 10.3.6,
- mac os x server 10.3.7,
- mac os x server 10.3.8,
- mac os x server 10.3.9,
- mandrake linux 10.0,
- mandrake linux 10.1,
- mandrake linux corporate server 3.0,
- mn100,
- modular messaging message storage server 1.1,
- modular messaging message storage server 2.0,
- propack 3.0,
- solaris 10.0,
- solaris 7.0,
- solaris 8.0,
- solaris 9.0,
- sunos 5.7,
- sunos 5.8,
- unixware 7.1.4
Weaknesses
References
Advisory
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: