CVE-2004-0804
CVSS5.0
发布时间 :2004-11-03 00:00:00
修订时间 :2010-08-21 00:21:18
NMCOP    

[原文]Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via a TIFF image that causes a divide-by-zero error when the number of row bytes is zero, a different vulnerability than CVE-2005-2452.


[CNNVD]kfax libtiff多个安全漏洞(CNNVD-200411-031)

        
        libtiff是负责对TIFF图象格式编码/解码的应用库。kfax是一款小型的显示FAX文件工具,使用到libtiff库。
        libtiff在处理传真文件时存在问题,远程攻击者可以利用这个漏洞进行缓冲区溢出攻击,可能以用户进程权限执行任意指令。
        kfax调用libtiff库处理.g3文件,攻击者可以构建畸形.g3文件,诱使用户处理,可导致发生缓冲区溢出,精心构建文件数据可能以用户进程权限执行任意指令。
        

- CVSS (基础分值)

CVSS分值: 5 [中等(MEDIUM)]
机密性影响: NONE [对系统的机密性无影响]
完整性影响: NONE [不会对系统完整性产生影响]
可用性影响: PARTIAL [可能会导致性能下降或中断资源访问]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: [--]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

产品及版本信息(CPE)暂不可用

- OVAL (用于检测的技术细节)

oval:org.mitre.oval:def:11711Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via a TIFF image that ca...
oval:org.mitre.oval:def:100115libtiff tif_dirread divide-by-zero Denial of Service
*OVAL详细的描述了检测该漏洞的方法,你可以从相关的OVAL定义中找到更多检测该漏洞的技术细节。

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0804
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2004-0804
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200411-031
(官方数据源) CNNVD

- 其它链接及资源

http://www.kb.cert.org/vuls/id/555304
(UNKNOWN)  CERT-VN  VU#555304
http://xforce.iss.net/xforce/xfdb/17755
(VENDOR_ADVISORY)  XF  libtiff-dos(17755)
http://www.redhat.com/support/errata/RHSA-2004-577.html
(VENDOR_ADVISORY)  REDHAT  RHSA-2004:577
http://www.redhat.com/support/errata/RHSA-2005-354.html
(UNKNOWN)  REDHAT  RHSA-2005:354
http://www.novell.com/linux/security/advisories/2004_38_libtiff.html
(UNKNOWN)  SUSE  SUSE-SA:2004:038
http://www.kde.org/info/security/advisory-20041209-2.txt
(UNKNOWN)  CONFIRM  http://www.kde.org/info/security/advisory-20041209-2.txt
http://www.debian.org/security/2004/dsa-567
(VENDOR_ADVISORY)  DEBIAN  DSA-567
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201072-1
(UNKNOWN)  SUNALERT  201072
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000888
(UNKNOWN)  CONECTIVA  CLA-2004:888
http://bugzilla.remotesensing.org/show_bug.cgi?id=111
(UNKNOWN)  MISC  http://bugzilla.remotesensing.org/show_bug.cgi?id=111
http://www.redhat.com/support/errata/RHSA-2005-021.html
(UNKNOWN)  REDHAT  RHSA-2005:021
http://www.mandriva.com/security/advisories?name=MDKSA-2005:052
(UNKNOWN)  MANDRAKE  MDKSA-2005:052
http://www.mandriva.com/security/advisories?name=MDKSA-2004:109
(UNKNOWN)  MANDRAKE  MDKSA-2004:109
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1
(UNKNOWN)  SUNALERT  101677

- 漏洞信息

kfax libtiff多个安全漏洞
中危 边界条件错误
2004-11-03 00:00:00 2009-02-05 00:00:00
远程※本地  
        
        libtiff是负责对TIFF图象格式编码/解码的应用库。kfax是一款小型的显示FAX文件工具,使用到libtiff库。
        libtiff在处理传真文件时存在问题,远程攻击者可以利用这个漏洞进行缓冲区溢出攻击,可能以用户进程权限执行任意指令。
        kfax调用libtiff库处理.g3文件,攻击者可以构建畸形.g3文件,诱使用户处理,可导致发生缓冲区溢出,精心构建文件数据可能以用户进程权限执行任意指令。
        

- 公告与补丁

        厂商补丁:
        KDE
        ---
        源代码升级已经修正此漏洞,建议用户更新使用。

- 漏洞信息 (F34737)

dsa-567.txt (PacketStormID:F34737)
2004-10-26 00:00:00
 
advisory,arbitrary
linux,debian
CVE-2004-0803,CVE-2004-0804,CVE-2004-0886
[点击下载]

Debian Security Advisory 567-1 - Several problems have been discovered in libtiff, the Tag Image File Format library for processing TIFF graphics files. An attacker could prepare a specially crafted TIFF graphic that would cause the client to execute arbitrary code or crash.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 567-1                     security@debian.org
http://www.debian.org/security/                             Martin Schulze
October 15th, 2004                      http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : tiff
Vulnerability  : heap overflows
Problem-Type   : remote
Debian-specific: no
CVE ID         : CAN-2004-0803 CAN-2004-0804 CAN-2004-0886

Several problems have been discovered in libtiff, the Tag Image File
Format library for processing TIFF graphics files.  An attacker could
prepare a specially crafted TIFF graphic that would cause the client
to execute arbitrary code or crash.  The Common Vulnerabilities and
Exposures Project has identified the following problems:

CAN-2004-0803

    Chris Evans discovered several problems in the RLE (run length
    encoding) decoders that could lead to arbitrary code execution.

CAN-2004-0804

    Matthias Clasen discovered a division by zero through an integer
    overflow.

CAN-2004-0886

    Dmitry V. Levin discovered several integer overflows that caused
    malloc issues which can result to either plain crash or memory
    corruption.


For the stable distribution (woody) these problems have been fixed in
version 3.5.5-6woody1.

For the unstable distribution (sid) these problems have been fixed in
version 3.6.1-2.

We recommend that you upgrade your libtiff package.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
- --------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/t/tiff/tiff_3.5.5-6woody1.dsc
      Size/MD5 checksum:      635 11a374e916d818c05a373feb04cab6a0
    http://security.debian.org/pool/updates/main/t/tiff/tiff_3.5.5-6woody1.diff.gz
      Size/MD5 checksum:    36717 6f4d137f7c935d57757313a610dbd389
    http://security.debian.org/pool/updates/main/t/tiff/tiff_3.5.5.orig.tar.gz
      Size/MD5 checksum:   693641 3b7199ba793dec6ca88f38bb0c8cc4d8

  Alpha architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_alpha.deb
      Size/MD5 checksum:   141424 18b6e6b621178c1419de8a13a0a62366
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_alpha.deb
      Size/MD5 checksum:   105148 875257fb73ba05a575d06650c130a545
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_alpha.deb
      Size/MD5 checksum:   423194 9796f3e82553cedb237f1b574570f143

  ARM architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_arm.deb
      Size/MD5 checksum:   116928 5ed91b9586d830e8da9a5086fc5a6e76
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_arm.deb
      Size/MD5 checksum:    90466 f04c381a418fd33602d1ba30158597d3
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_arm.deb
      Size/MD5 checksum:   404262 30f13bfdf54cfca30ee5ca0f6c6d0e4e

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_i386.deb
      Size/MD5 checksum:   112068 d15dfdf84f010be08799d456726e1d9d
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_i386.deb
      Size/MD5 checksum:    81054 293f5c99f0a589917257ec7fee0b92fe
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_i386.deb
      Size/MD5 checksum:   387052 9606adb1668decf5ac1ee02a94298e85

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_ia64.deb
      Size/MD5 checksum:   158774 80c1b7ad68ecc78091ea95414125e81c
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_ia64.deb
      Size/MD5 checksum:   135386 b17f87aa0ad98fc50aa8c137a6f5089c
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_ia64.deb
      Size/MD5 checksum:   446496 757f3b6cc9d3f1ec5a2dfb1c3485caf3

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_hppa.deb
      Size/MD5 checksum:   128298 46dece015f0282bca0af7f6e740e9d31
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_hppa.deb
      Size/MD5 checksum:   106788 b837005b41c54c341cbd61e8fdb581ff
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_hppa.deb
      Size/MD5 checksum:   420346 3a2b91ee22af99eec3ab42d81cf9d59f

  Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_m68k.deb
      Size/MD5 checksum:   107302 0c702a3e5c2ad7ad7bd96dae64fa2d61
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_m68k.deb
      Size/MD5 checksum:    79770 d67f4347d35bf898a6ab1914cb53a42f
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_m68k.deb
      Size/MD5 checksum:   380218 42e6f07cf2e70de01ca40ac4a97254bf

  Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_mips.deb
      Size/MD5 checksum:   124048 85d8c8cbb62cc62c876bf4ed721027cf
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_mips.deb
      Size/MD5 checksum:    87840 5f3312f22b0f345c7eae434f5b871993
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_mips.deb
      Size/MD5 checksum:   410770 be817ddffa91c423b55fda3388d7ce48

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_mipsel.deb
      Size/MD5 checksum:   123558 42594e9270de16ff802c11eccf7a0efb
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_mipsel.deb
      Size/MD5 checksum:    88198 a8f0abe9205431caf94dce77d11ac477
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_mipsel.deb
      Size/MD5 checksum:   410860 68a12ef6d37fc575105c4ceb9b766949

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_powerpc.deb
      Size/MD5 checksum:   116042 2258da94549ae05ffae643bc40790487
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_powerpc.deb
      Size/MD5 checksum:    89424 c8d782561a299ffb65ea84b59d88117a
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_powerpc.deb
      Size/MD5 checksum:   402372 1eca24adda52b40c7a8d789fdeb3cb2e

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_s390.deb
      Size/MD5 checksum:   116870 dcddc86a0d96296c07076391adc9d754
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_s390.deb
      Size/MD5 checksum:    91742 40c1de704b191e4abb65af8a4b7fd75d
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_s390.deb
      Size/MD5 checksum:   395332 86d351b75f1f146ddad6d562ca77005c

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_sparc.deb
      Size/MD5 checksum:   132888 9ed9db78d727ba8bfbb25c1e68b03bf2
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_sparc.deb
      Size/MD5 checksum:    88556 a4069600bd9295a27d4eb6e9e0995495
    http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_sparc.deb
      Size/MD5 checksum:   397026 149e12055c5711129552fa938b5af431


  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFBcA4UW5ql+IAeqTIRAgMFAKC3Kbs2MxW5XlOa3aK9oo76W8wt9gCfXzyA
fD+15yHAK6bw15bB4ejaGV8=
=KPqY
-----END PGP SIGNATURE-----

    

- 漏洞信息 (F34652)

DSA-561-1-tiff--heap-overflows (PacketStormID:F34652)
2004-10-18 00:00:00
 
advisory,arbitrary
linux,debian
CVE-2004-0804
[点击下载]

Debian Security Advisory DSA-567-1. This details which versions of libtiff are affected by issues where specially crafted TIFF graphics could cause a vulnerable client to execute arbitrary code or crash.

Debian Security Advisory

DSA-567-1 tiff -- heap overflows

   Date Reported:
          15 Oct 2004
   Affected Packages:
          [9]tiff
   Vulnerable:
          Yes
   Security database references:
          In      Mitre's      CVE     dictionary:     [10]CAN-2004-0803,
          [11]CAN-2004-0804, [12]CAN-2004-0886.
   More information:
          Several problems have been discovered in libtiff, the Tag Image
          File  Format  library  for  processing  TIFF graphics files. An
          attacker  could  prepare  a specially crafted TIFF graphic that
          would  cause the client to execute arbitrary code or crash. The
          Common Vulnerabilities and Exposures Project has identified the
          following problems:
          + [13]CAN-2004-0803
            Chris  Evans  discovered  several  problems  in  the RLE (run
            length  encoding)  decoders that could lead to arbitrary code
            execution.
          + [14]CAN-2004-0804
            Matthias  Clasen  discovered  a  division  by zero through an
            integer overflow.
          + [15]CAN-2004-0886
            Dmitry  V.  Levin  discovered  several integer overflows that
            caused  malloc  issues which can result to either plain crash
            or memory corruption.
          For  the  stable  distribution (woody) these problems have been
          fixed in version 3.5.5-6woody1.
          For  the  unstable  distribution (sid) these problems have been
          fixed in version 3.6.1-2.
          We recommend that you upgrade your libtiff package.
   Fixed in:

  Debian GNU/Linux 3.0 (woody)

        Source:
                [16]http://security.debian.org/pool/updates/main/t/tiff/t
                iff_3.5.5-6woody1.dsc
                [17]http://security.debian.org/pool/updates/main/t/tiff/t
                iff_3.5.5-6woody1.diff.gz
                [18]http://security.debian.org/pool/updates/main/t/tiff/t
                iff_3.5.5.orig.tar.gz

        Alpha:
                [19]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff-tools_3.5.5-6woody1_alpha.deb
                [20]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g_3.5.5-6woody1_alpha.deb
                [21]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g-dev_3.5.5-6woody1_alpha.deb

        ARM:
                [22]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff-tools_3.5.5-6woody1_arm.deb
                [23]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g_3.5.5-6woody1_arm.deb
                [24]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g-dev_3.5.5-6woody1_arm.deb

        Intel IA-32:
                [25]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff-tools_3.5.5-6woody1_i386.deb
                [26]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g_3.5.5-6woody1_i386.deb
                [27]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g-dev_3.5.5-6woody1_i386.deb

        Intel IA-64:
                [28]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff-tools_3.5.5-6woody1_ia64.deb
                [29]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g_3.5.5-6woody1_ia64.deb
                [30]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g-dev_3.5.5-6woody1_ia64.deb

        HPPA:
                [31]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff-tools_3.5.5-6woody1_hppa.deb
                [32]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g_3.5.5-6woody1_hppa.deb
                [33]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g-dev_3.5.5-6woody1_hppa.deb

        Motorola 680x0:
                [34]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff-tools_3.5.5-6woody1_m68k.deb
                [35]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g_3.5.5-6woody1_m68k.deb
                [36]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g-dev_3.5.5-6woody1_m68k.deb

        Big endian MIPS:
                [37]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff-tools_3.5.5-6woody1_mips.deb
                [38]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g_3.5.5-6woody1_mips.deb
                [39]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g-dev_3.5.5-6woody1_mips.deb

        Little endian MIPS:
                [40]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff-tools_3.5.5-6woody1_mipsel.deb
                [41]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g_3.5.5-6woody1_mipsel.deb
                [42]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g-dev_3.5.5-6woody1_mipsel.deb

        PowerPC:
                [43]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff-tools_3.5.5-6woody1_powerpc.deb
                [44]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g_3.5.5-6woody1_powerpc.deb
                [45]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g-dev_3.5.5-6woody1_powerpc.deb

        IBM S/390:
                [46]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff-tools_3.5.5-6woody1_s390.deb
                [47]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g_3.5.5-6woody1_s390.deb
                [48]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g-dev_3.5.5-6woody1_s390.deb

        Sun Sparc:
                [49]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff-tools_3.5.5-6woody1_sparc.deb
                [50]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g_3.5.5-6woody1_sparc.deb
                [51]http://security.debian.org/pool/updates/main/t/tiff/l
                ibtiff3g-dev_3.5.5-6woody1_sparc.deb

          MD5  checksums  of  the  listed  files  are  available  in  the
          [52]original advisory.

    

- 漏洞信息

10909
LibTIFF tif_dirread Malformed Image Overflow DoS
Remote / Network Access Denial of Service, Input Manipulation
Loss of Integrity, Loss of Availability
Exploit Unknown Vendor Verified

- 漏洞描述

A remote overflow exists in libTIFF. LibTIFF divides by zero when receiving a TIFF image where the row bytes are equal to zero resulting in a integer overflow. With a specially crafted TIFF image, an attacker can cause the application to crash resulting in a loss of availability.

- 时间线

2004-10-18 Unknow
Unknow Unknow

- 解决方案

Currently, there are no known workarounds or upgrades to correct this issue. However, Debian has released a patch to address this vulnerability.

- 相关参考

- 漏洞作者

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站