← Vulnerability feed

Vulnerability record · CVE-2004-1308 · published 10 January 2005

CVE-2004-1308: Libtiff vulnerability

Libtiff · Libtiff

Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.

10.0 CVSS 2.0 High EPSS 15% · top 3.4%
10.0CVSS 2.0 base score
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
32References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000920
http://lists.apple.com/archives/security-announce/2005/May/msg00001.html
http://secunia.com/advisories/13776
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201072-1
http://www.debian.org/security/2004/dsa-617
http://www.idefense.com/application/poi/display?id=174&type=vulnerabilities ExploitPatchVendor Advisory
http://www.kb.cert.org/vuls/id/125598 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2005:052
http://www.novell.com/linux/security/advisories/2005_01_libtiff_tiff.html
http://www.redhat.com/support/errata/RHSA-2005-019.html
http://www.redhat.com/support/errata/RHSA-2005-035.html
http://www.us-cert.gov/cas/techalerts/TA05-136A.html US Government Resource
https://exchange.xforce.ibmcloud.com/vulnerabilities/18637
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100117
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9392
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000920
http://lists.apple.com/archives/security-announce/2005/May/msg00001.html
http://secunia.com/advisories/13776
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201072-1
http://www.debian.org/security/2004/dsa-617
http://www.idefense.com/application/poi/display?id=174&type=vulnerabilities ExploitPatchVendor Advisory
http://www.kb.cert.org/vuls/id/125598 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2005:052
http://www.novell.com/linux/security/advisories/2005_01_libtiff_tiff.html
http://www.redhat.com/support/errata/RHSA-2005-019.html
http://www.redhat.com/support/errata/RHSA-2005-035.html
http://www.us-cert.gov/cas/techalerts/TA05-136A.html US Government Resource
https://exchange.xforce.ibmcloud.com/vulnerabilities/18637
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100117
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9392

Track CVE-2004-1308 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0929Libtiff vulnerabilityHeap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPE…EPSS 8.2%9.8CVE-2016-9540Libtiff memory buffer overflow vulnerabilitytools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width. Reported as MSVR 35103, aka "cpStr…EPSS 3.6%9.8CVE-2016-9539Libtiff memory buffer overflow vulnerabilitytools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer(). Reported as MSVR 35092.EPSS 3.0%9.8CVE-2016-9538Libtiff integer overflow vulnerabilitytools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow. Reported as MSVR 35…EPSS 3.4%9.8CVE-2016-9537Libtiff memory buffer overflow vulnerabilitytools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers. Reported as MSVR 35093, MSVR 35096, and MSVR 35097.EPSS 3.1%9.8CVE-2016-9536Libtiff memory buffer overflow vulnerabilitytools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip(). Reported as MSVR 350…EPSS 3.1%9.8CVE-2016-9535Libtiff memory buffer overflow vulnerabilitytif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mo…EPSS 4.8%9.8CVE-2016-9534Libtiff memory buffer overflow vulnerabilitytif_write.c in libtiff 4.0.6 has an issue in the error code path of TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp members. Reported …EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2004-1308), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.