Lucene search

K
osvGoogleOSV:DSA-617-1
HistoryDec 24, 2004 - 12:00 a.m.

libtiff - insufficient input validation

2004-12-2400:00:00
Google
osv.dev
10

0.129 Low

EPSS

Percentile

95.5%

“infamous41md” discovered a problem in libtiff, the Tag Image File
Format library for processing TIFF graphics files. Upon reading a
TIFF file it is possible to allocate a zero sized buffer and write to
it which would lead to the execution of arbitrary code.

For the stable distribution (woody) this problem has been fixed in
version 3.5.5-6.woody3.

For the unstable distribution (sid) this problem has been fixed in
version 3.6.1-4.

We recommend that you upgrade your libtiff packages immediately.