Sun Microsystems Inc. Information for VU#539110
LibTIFF vulnerable to integer overflow in the TIFFFetchStrip() routine
- Vendor Information Help Date Notified: 21 Jan 2005
- Statement Date:
- Date Updated: 02 Feb 2005
Sun is affected by this libtiff vulnerability (CERT VU#539110) which corresponds to CVE CAN-2004-1307 and is also affected by the following libtiff vulnerabilities: CAN-2004-1308 (CERT VU#125598), CAN-2004-0803, CAN-2004-0804, and CAN-2004-0886. The following libraries in Solaris are affected:
Solaris 7, 8, 9 - OpenWindows
Solaris 9 - Sun Freeware
The libtiff.so library in the Sun Java Desktop System (JDS) is affected by this issue in JDS release 2003 and JDS release 2.
Sun is generating patches to update libtiff to v3.7.1 for the above affected libraries and will be publishing Sun Alerts for these libtiff vulnerabilities shortly.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.