Back to Database
Status published
Medium
CVE-2004-0886
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote...
Vulnerability Description
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-0886
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.redhat.com/support/errata/RHSA-2004-577.html
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:109
- http://www.redhat.com/support/errata/RHSA-2005-021.html
- http://www.ciac.org/ciac/bulletins/p-015.shtml
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-201072-1
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9907
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1
- http://www.novell.com/linux/security/advisories/2004_38_libtiff.html
- http://www.kb.cert.org/vuls/id/687568
- http://securitytracker.com/id?1011674
- http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000888
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:052
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17715
- http://www.trustix.org/errata/2004/0054/
- http://www.kde.org/info/security/advisory-20041209-2.txt
- http://www.redhat.com/support/errata/RHSA-2005-354.html
- http://secunia.com/advisories/12818
- http://www.securityfocus.com/bid/11406
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100116
- http://www.debian.org/security/2004/dsa-567
- http://marc.info/?l=bugtraq&m=109779465621929&w=2
More from libtiff
View All →CVE-2023-3316
A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones.
Medium
5.9
CVE-2023-0804
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609,...
Medium
6.8
CVE-2023-0803
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3516,...
Medium
6.8
CVE-2023-0802
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3724,...
Medium
6.8
CVE-2023-0801
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368,...
Medium
6.8
Affected Vendor
libtiff
View all reports →Affected Software
libtiff, pdf library, wxgtk2, mac os x, mac os x server, kde, mandrake linux, enterprise linux, enterprise linux desktop, fedora core, linux advanced workstation, suse linux, secure linux
Vulnerable Versions:
3.4, 3.5.1, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.7, 3.6.0, 3.6.1, 5.0.2, 2.5_.0, 10.2, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.5, 10.2.6, 10.2.7, 10.2.8, 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 3.2, 3.2.1, 3.2.2, 3.2.3, 3.3, 3.3.1, 10.0, 2.1, 3.0, core_2.0, 1.0, 8, 8.1, 8.2, 9.0, 9.1, 1.5, 2.0
Timeline
Official Publish:
October 26th, 2004
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.