Upstream information
Description
Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having critical severity.
| National Vulnerability Database | |
|---|---|
| Base Score | 10 | 
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C | 
| Access Vector | Network | 
| Access Complexity | Low | 
| Authentication | None | 
| Confidentiality Impact | Complete | 
| Integrity Impact | Complete | 
| Availability Impact | Complete | 
SUSE Security Advisories:
- SUSE-SA:2005:001, published Monday, Jan 10th 2005 11:30 MET
 
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 01:05:43 2013CVE page last modified: Tue Dec 19 11:09:20 2023