Sun Microsystems Inc. Information for VU#539110

LibTIFF vulnerable to integer overflow in the TIFFFetchStrip() routine

Status

Affected

Vendor Statement

Sun is affected by this libtiff vulnerability (CERT VU#539110) which corresponds to CVE CAN-2004-1307 and is also affected by the following libtiff vulnerabilities: CAN-2004-1308 (CERT VU#125598), CAN-2004-0803, CAN-2004-0804, and CAN-2004-0886. The following libraries in Solaris are affected:


    Solaris 7, 8, 9 - OpenWindows
    /usr/openwin/lib/libtiff.so.3

    Solaris 9 - Sun Freeware
    /usr/sfw/lib/libtiff.so.3


The libtiff.so library in the Sun Java Desktop System (JDS) is affected by this issue in JDS release 2003 and JDS release 2.

Sun is generating patches to update libtiff to v3.7.1 for the above affected libraries and will be publishing Sun Alerts for these libtiff vulnerabilities shortly.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References

None

Addendum

US-CERT has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.