Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-1544Improper Restriction of Operations within the Bounds of a Memory Buffer in Tiff

7 documents7 sources
Severity
7.5HIGHNVD
EPSS
15.7%
top 5.29%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMay 14
Latest updateMay 3

Description

Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDlibtiff/libtiff12 versions+11
debiandebian/tiff< tiff 3.7.2-3 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-45px-6f9w-fmpf: Stack-based buffer overflow in libTIFF before 32022-05-03
OSV
CVE-2005-1544: Stack-based buffer overflow in libTIFF before 32005-05-14

💥Exploits & PoCs

1
Exploit-DB
LibTiff 3.7.1 - BitsPerSample Tag Local Buffer Overflow2006-03-05

📋Vendor Advisories

3
Ubuntu
TIFF library vulnerability2005-05-20
Debian
CVE-2005-1544: tiff - Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to e...2005
Red Hat
CVE-2005-1544: Stack-based buffer overflow in libTIFF before 3