Summary
The remote host is missing an update to tiff
announced via advisory DSA 567-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20567-1
Insight
Several problems have been discovered in libtiff, the Tag Image File Format library for processing TIFF graphics files. An attacker could prepare a specially crafted TIFF graphic that would cause the client to execute arbitrary code or crash. The Common Vulnerabilities and Exposures Project has identified the following problems:
CVE-2004-0803
Chris Evans discovered several problems in the RLE (run length encoding) decoders that could lead to arbitrary code execution.
CVE-2004-0804
Matthias Clasen discovered a division by zero through an integer overflow.
CVE-2004-0886
Dmitry V. Levin discovered several integer overflows that caused malloc issues which can result to either plain crash or memory corruption.
For the stable distribution (woody) these problems have been fixed in version 3.5.5-6woody1.
For the unstable distribution (sid) these problems have been fixed in version 3.6.1-2.
We recommend that you upgrade your libtiff package.
Severity
Classification
-
CVE CVE-2004-0803, CVE-2004-0804, CVE-2004-0886 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities