CVE-2004-0929
published 2005-01-27CVE-2004-0929: Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support)…
PriorityP340critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.09%
94.2th percentile
Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support) option, allows remote attackers to execute arbitrary code via a malformed TIFF image.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| libtiff | libtiff | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.idefense.com/application/poi/display?id=154&type=vulnerabilitieshttp://www.kb.cert.org/vuls/id/129910http://www.novell.com/linux/security/advisories/2004_38_libtiff.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/17843http://www.idefense.com/application/poi/display?id=154&type=vulnerabilitieshttp://www.kb.cert.org/vuls/id/129910http://www.novell.com/linux/security/advisories/2004_38_libtiff.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/17843
2005-01-27
Published