ID

VAR-200501-0287


CVE

CVE-2004-0886


TITLE

LibTIFF contains multiple integer overflows

Trust: 1.6

sources: CERT/CC: VU#687568 // CERT/CC: VU#687568

DESCRIPTION

Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls. Apple Mac OS X with Bluetooth support may unintentionally allow files to be exchanged with other systems by default. Apple Mac OS X Directory Service utilities use external programs insecurely, potentially allowing an attacker to execute arbitrary code. Multiple integer overflows in the LibTIFF library may allow an attacker to execute arbitrary code. Multiple integer overflows in the LibTIFF library may allow an attacker to execute arbitrary code. LibTIFF is affected by multiple buffer-overflow vulnerabilities because the software fails to properly perform boundary checks before copying user-supplied strings into finite process buffers. An attacker may leverage these issues to execute arbitrary code on a vulnerable computer with the privileges of the user running a vulnerable application, facilitating unauthorized access. The attacker may also leverage these issues to crash the affected application. libtiff is an application library responsible for encoding/decoding the TIFF image format. ---------------------------------------------------------------------- Want a new IT Security job? Vacant positions at Secunia: http://secunia.com/secunia_vacancies/ ---------------------------------------------------------------------- TITLE: Mac OS X Security Update Fixes Multiple Vulnerabilities SECUNIA ADVISORY ID: SA15227 VERIFY ADVISORY: http://secunia.com/advisories/15227/ CRITICAL: Highly critical IMPACT: Security Bypass, Spoofing, Exposure of sensitive information, Privilege escalation, System access WHERE: >From remote OPERATING SYSTEM: Apple Macintosh OS X http://secunia.com/product/96/ DESCRIPTION: Apple has issued a security update for Mac OS X, which fixes various vulnerabilities. 1) A boundary error in htdigest can be exploited to cause a buffer overflow by passing an overly long realm argument. NOTE: htdigest is by default only locally accessible and not setuid / setgid. 2) An integer overflow error in the AppKit component when processing TIFF files can be exploited by malicious people to compromise a user's system. For more information: SA13607 3) An error in the AppKit component when parsing certain TIFF images can result in an invalid call to the "NXSeek()" function, which will crash an affected Cocoa application. 4) An error within the handling of AppleScript can be exploited to display code to a user that is different than the code, which will actually run. 5) An error in the Bluetooth support may cause Bluetooth-enabled systems to share files via the Bluetooth file exchange service without notifying the user properly. 6) An input validation error can be exploited to access arbitrary files on a Bluetooth-enabled system using directory traversal attacks via the Bluetooth file and object exchange services. 7) The chfn, chpass, and chsh utilities invoke certain external helper programs insecurely, which can be exploited by malicious, local users to gain escalated privileges. 8) A vulnerability in Finder can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges due to insecure creation of ".DS_Store" files. For more information: SA14188 9) A boundary error within the Foundation framework when handling environment variables can be exploited to cause a buffer overflow and may allow execution of arbitrary code. 10) An error in Help Viewer can be exploited to run JavaScript without the normally imposed security restrictions. 11) A security issue in the LDAP functionality may under certain circumstances result in passwords initially being stored in plain text. 12) Errors within the parsing of XPM files can potentially be exploited by malicious people to compromise a vulnerable system. For more information: SA12549 13) An error in lukemftpd can be exploited by malicious users to bypass chroot restrictions. In order to restrict users to their home directory, both their full name and short name must be listed in the "/etc/ftpchroot" file. However, the problem is that users can change their full name and thereby bypass this restriction. 15) When enabling the HTTP proxy service in Server Admin, it is by default possible for everyone (including users on the Internet) to use the proxy service. 16) A vulnerability in sudo within the environment clearing can be exploited by malicious, local users to gain escalated privileges. For more information: SA13199 17) An error in the Terminal utility can be exploited to inject data via malicious input containing escape sequences in window titles. 18) An error in the Terminal utility can be exploited to inject commands into a user's Terminal session via malicious input containing escape characters in x-man-path URIs. SOLUTION: Apply Security Update 2005-005. Security Update 2005-005 (Client): http://www.apple.com/support/downloads/securityupdate2005005client.html Security Update 2005-005 (Server): http://www.apple.com/support/downloads/securityupdate2005005server.html PROVIDED AND/OR DISCOVERED BY: 1) JxT 3) Henrik Dalgaard 4) David Remahl 5) Kevin Finisterre, digitalmunition.com. 6) Kevin Finisterre, digitalmunition.com. 10) David Remahl 13) Rob Griffiths 14) Nico 17) David Remahl 18) David Remahl 19) Pieter de Boer ORIGINAL ADVISORY: Apple: http://docs.info.apple.com/article.html?artnum=301528 David Remahl: http://remahl.se/david/vuln/004/ http://remahl.se/david/vuln/010/ http://remahl.se/david/vuln/011/ http://remahl.se/david/vuln/012/ digitalmunition.com: http://www.digitalmunition.com/DMA[2005-0502a].txt iDEFENSE: http://www.idefense.com/application/poi/display?id=239&type=vulnerabilities OTHER REFERENCES: SA12549: http://secunia.com/advisories/12549/ SA13199: http://secunia.com/advisories/13199/ SA13607: http://secunia.com/advisories/13607/ SA14188: http://secunia.com/advisories/14188/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ---------------------------------------------------------------------- . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Debian Security Advisory DSA 567-1 security@debian.org http://www.debian.org/security/ Martin Schulze October 15th, 2004 http://www.debian.org/security/faq - -------------------------------------------------------------------------- Package : tiff Vulnerability : heap overflows Problem-Type : remote Debian-specific: no CVE ID : CAN-2004-0803 CAN-2004-0804 CAN-2004-0886 Several problems have been discovered in libtiff, the Tag Image File Format library for processing TIFF graphics files. The Common Vulnerabilities and Exposures Project has identified the following problems: CAN-2004-0803 Chris Evans discovered several problems in the RLE (run length encoding) decoders that could lead to arbitrary code execution. CAN-2004-0804 Matthias Clasen discovered a division by zero through an integer overflow. CAN-2004-0886 Dmitry V. For the stable distribution (woody) these problems have been fixed in version 3.5.5-6woody1. For the unstable distribution (sid) these problems have been fixed in version 3.6.1-2. We recommend that you upgrade your libtiff package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: http://security.debian.org/pool/updates/main/t/tiff/tiff_3.5.5-6woody1.dsc Size/MD5 checksum: 635 11a374e916d818c05a373feb04cab6a0 http://security.debian.org/pool/updates/main/t/tiff/tiff_3.5.5-6woody1.diff.gz Size/MD5 checksum: 36717 6f4d137f7c935d57757313a610dbd389 http://security.debian.org/pool/updates/main/t/tiff/tiff_3.5.5.orig.tar.gz Size/MD5 checksum: 693641 3b7199ba793dec6ca88f38bb0c8cc4d8 Alpha architecture: http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_alpha.deb Size/MD5 checksum: 141424 18b6e6b621178c1419de8a13a0a62366 http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_alpha.deb Size/MD5 checksum: 105148 875257fb73ba05a575d06650c130a545 http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_alpha.deb Size/MD5 checksum: 423194 9796f3e82553cedb237f1b574570f143 ARM architecture: http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_arm.deb Size/MD5 checksum: 116928 5ed91b9586d830e8da9a5086fc5a6e76 http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_arm.deb Size/MD5 checksum: 90466 f04c381a418fd33602d1ba30158597d3 http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_arm.deb Size/MD5 checksum: 404262 30f13bfdf54cfca30ee5ca0f6c6d0e4e Intel IA-32 architecture: http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_i386.deb Size/MD5 checksum: 112068 d15dfdf84f010be08799d456726e1d9d http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_i386.deb Size/MD5 checksum: 81054 293f5c99f0a589917257ec7fee0b92fe http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_i386.deb Size/MD5 checksum: 387052 9606adb1668decf5ac1ee02a94298e85 Intel IA-64 architecture: http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_ia64.deb Size/MD5 checksum: 158774 80c1b7ad68ecc78091ea95414125e81c http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_ia64.deb Size/MD5 checksum: 135386 b17f87aa0ad98fc50aa8c137a6f5089c http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_ia64.deb Size/MD5 checksum: 446496 757f3b6cc9d3f1ec5a2dfb1c3485caf3 HP Precision architecture: http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_hppa.deb Size/MD5 checksum: 128298 46dece015f0282bca0af7f6e740e9d31 http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_hppa.deb Size/MD5 checksum: 106788 b837005b41c54c341cbd61e8fdb581ff http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_hppa.deb Size/MD5 checksum: 420346 3a2b91ee22af99eec3ab42d81cf9d59f Motorola 680x0 architecture: http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_m68k.deb Size/MD5 checksum: 107302 0c702a3e5c2ad7ad7bd96dae64fa2d61 http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_m68k.deb Size/MD5 checksum: 79770 d67f4347d35bf898a6ab1914cb53a42f http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_m68k.deb Size/MD5 checksum: 380218 42e6f07cf2e70de01ca40ac4a97254bf Big endian MIPS architecture: http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_mips.deb Size/MD5 checksum: 124048 85d8c8cbb62cc62c876bf4ed721027cf http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_mips.deb Size/MD5 checksum: 87840 5f3312f22b0f345c7eae434f5b871993 http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_mips.deb Size/MD5 checksum: 410770 be817ddffa91c423b55fda3388d7ce48 Little endian MIPS architecture: http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_mipsel.deb Size/MD5 checksum: 123558 42594e9270de16ff802c11eccf7a0efb http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_mipsel.deb Size/MD5 checksum: 88198 a8f0abe9205431caf94dce77d11ac477 http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_mipsel.deb Size/MD5 checksum: 410860 68a12ef6d37fc575105c4ceb9b766949 PowerPC architecture: http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_powerpc.deb Size/MD5 checksum: 116042 2258da94549ae05ffae643bc40790487 http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_powerpc.deb Size/MD5 checksum: 89424 c8d782561a299ffb65ea84b59d88117a http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_powerpc.deb Size/MD5 checksum: 402372 1eca24adda52b40c7a8d789fdeb3cb2e IBM S/390 architecture: http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_s390.deb Size/MD5 checksum: 116870 dcddc86a0d96296c07076391adc9d754 http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_s390.deb Size/MD5 checksum: 91742 40c1de704b191e4abb65af8a4b7fd75d http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_s390.deb Size/MD5 checksum: 395332 86d351b75f1f146ddad6d562ca77005c Sun Sparc architecture: http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_sparc.deb Size/MD5 checksum: 132888 9ed9db78d727ba8bfbb25c1e68b03bf2 http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_sparc.deb Size/MD5 checksum: 88556 a4069600bd9295a27d4eb6e9e0995495 http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_sparc.deb Size/MD5 checksum: 397026 149e12055c5711129552fa938b5af431 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main Mailing list: debian-security-announce@lists.debian.org Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.5 (GNU/Linux) iD8DBQFBcA4UW5ql+IAeqTIRAgMFAKC3Kbs2MxW5XlOa3aK9oo76W8wt9gCfXzyA fD+15yHAK6bw15bB4ejaGV8= =KPqY -----END PGP SIGNATURE-----

Trust: 7.92

sources: NVD: CVE-2004-0886 // CERT/CC: VU#354486 // CERT/CC: VU#258390 // CERT/CC: VU#356070 // CERT/CC: VU#539110 // CERT/CC: VU#706838 // CERT/CC: VU#331694 // CERT/CC: VU#687568 // CERT/CC: VU#687568 // JVNDB: JVNDB-2004-000445 // BID: 11406 // VULHUB: VHN-9316 // PACKETSTORM: 37530 // PACKETSTORM: 34737

AFFECTED PRODUCTS

vendor:apple computermodel: - scope: - version: -

Trust: 6.4

vendor:redhatmodel:enterprise linuxscope:eqversion:2.1

Trust: 1.6

vendor:trustixmodel:secure linuxscope:eqversion:2.1

Trust: 1.3

vendor:trustixmodel:secure linuxscope:eqversion:2.0

Trust: 1.3

vendor:trustixmodel:secure linuxscope:eqversion:1.5

Trust: 1.3

vendor:susemodel:linuxscope:eqversion:8.1

Trust: 1.3

vendor:pdflibmodel:pdf libraryscope:eqversion:5.0.2

Trust: 1.3

vendor:libtiffmodel:libtiffscope:eqversion:3.6.1

Trust: 1.3

vendor:libtiffmodel:libtiffscope:eqversion:3.6.0

Trust: 1.3

vendor:libtiffmodel:libtiffscope:eqversion:3.5.7

Trust: 1.3

vendor:libtiffmodel:libtiffscope:eqversion:3.5.5

Trust: 1.3

vendor:libtiffmodel:libtiffscope:eqversion:3.5.4

Trust: 1.3

vendor:libtiffmodel:libtiffscope:eqversion:3.5.3

Trust: 1.3

vendor:libtiffmodel:libtiffscope:eqversion:3.5.2

Trust: 1.3

vendor:libtiffmodel:libtiffscope:eqversion:3.5.1

Trust: 1.3

vendor:libtiffmodel:libtiffscope:eqversion:3.4

Trust: 1.3

vendor:kdemodel:kdescope:eqversion:3.3.1

Trust: 1.3

vendor:kdemodel:kdescope:eqversion:3.3

Trust: 1.3

vendor:kdemodel:kdescope:eqversion:3.2.3

Trust: 1.3

vendor:kdemodel:kdescope:eqversion:3.2.2

Trust: 1.3

vendor:kdemodel:kdescope:eqversion:3.2.1

Trust: 1.3

vendor:kdemodel:kdescope:eqversion:3.2

Trust: 1.3

vendor:applemodel:mac os x serverscope:eqversion:10.2.8

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2.6

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2.5

Trust: 1.0

vendor:redhatmodel:fedora corescope:eqversion:core_2.0

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.2.5

Trust: 1.0

vendor:redhatmodel:enterprise linuxscope:eqversion:3.0

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.2.6

Trust: 1.0

vendor:susemodel:linuxscope:eqversion:1.0

Trust: 1.0

vendor:susemodel:linuxscope:eqversion:9.1

Trust: 1.0

vendor:redhatmodel:enterprise linux desktopscope:eqversion:3.0

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.3.6

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2.1

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.3.6

Trust: 1.0

vendor:wxgtk2model:wxgtk2scope:eqversion:2.5_.0

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.3.1

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.2.1

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2.4

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.2.4

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2.3

Trust: 1.0

vendor:mandrakesoftmodel:mandrake linuxscope:eqversion:10.0

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.2.3

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.3.5

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.3.1

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.3.4

Trust: 1.0

vendor:redhatmodel:linux advanced workstationscope:eqversion:2.1

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.3.4

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.3.5

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2.2

Trust: 1.0

vendor:wxgtk2model:wxgtk2scope:eqversion:*

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2.7

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.2.2

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.2.7

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.3.3

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.3.3

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.3

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.3

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.2

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.3.2

Trust: 1.0

vendor:susemodel:linuxscope:eqversion:9.0

Trust: 1.0

vendor:susemodel:linuxscope:eqversion:8

Trust: 1.0

vendor:susemodel:linuxscope:eqversion:8.2

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.3.2

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2.8

Trust: 1.0

vendor:red hatmodel: - scope: - version: -

Trust: 0.8

vendor:sun microsystemsmodel: - scope: - version: -

Trust: 0.8

vendor:cybertrustmodel:asianux serverscope:eqversion:2.0

Trust: 0.8

vendor:cybertrustmodel:asianux serverscope:eqversion:2.1

Trust: 0.8

vendor:cybertrustmodel:asianux serverscope:eqversion:3.0

Trust: 0.8

vendor:cybertrustmodel:asianux serverscope:eqversion:3.0 (x86-64)

Trust: 0.8

vendor:sun microsystemsmodel:solarisscope:eqversion:10 (sparc)

Trust: 0.8

vendor:sun microsystemsmodel:solarisscope:eqversion:10 (x86)

Trust: 0.8

vendor:sun microsystemsmodel:solarisscope:eqversion:7.0 (sparc)

Trust: 0.8

vendor:sun microsystemsmodel:solarisscope:eqversion:7.0 (x86)

Trust: 0.8

vendor:sun microsystemsmodel:solarisscope:eqversion:8 (sparc)

Trust: 0.8

vendor:sun microsystemsmodel:solarisscope:eqversion:8 (x86)

Trust: 0.8

vendor:sun microsystemsmodel:solarisscope:eqversion:9 (sparc)

Trust: 0.8

vendor:sun microsystemsmodel:solarisscope:eqversion:9 (x86)

Trust: 0.8

vendor:turbo linuxmodel:turbolinuxscope:eqversion:10_f

Trust: 0.8

vendor:turbo linuxmodel:turbolinux appliance serverscope:eqversion:1.0 (hosting)

Trust: 0.8

vendor:turbo linuxmodel:turbolinux appliance serverscope:eqversion:1.0 (workgroup)

Trust: 0.8

vendor:turbo linuxmodel:turbolinux desktopscope:eqversion:10

Trust: 0.8

vendor:turbo linuxmodel:turbolinux serverscope:eqversion:10

Trust: 0.8

vendor:turbo linuxmodel:turbolinux serverscope:eqversion:7

Trust: 0.8

vendor:turbo linuxmodel:turbolinux serverscope:eqversion:8

Trust: 0.8

vendor:turbo linuxmodel:turbolinux workstationscope:eqversion:7

Trust: 0.8

vendor:turbo linuxmodel:turbolinux workstationscope:eqversion:8

Trust: 0.8

vendor:turbo linuxmodel:homescope: - version: -

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:2.1 (as)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:2.1 (es)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:2.1 (ws)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:3 (as)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:3 (es)

Trust: 0.8

vendor:red hatmodel:enterprise linuxscope:eqversion:3 (ws)

Trust: 0.8

vendor:red hatmodel:enterprise linux desktopscope:eqversion:3.0

Trust: 0.8

vendor:red hatmodel:linux advanced workstationscope:eqversion:2.1

Trust: 0.8

vendor:wxgtk2model:wxgtk2scope:eqversion:2.5.0

Trust: 0.3

vendor:wxgtk2model:wxgtk2scope: - version: -

Trust: 0.3

vendor:trustixmodel:secure enterprise linuxscope:eqversion:2.0

Trust: 0.3

vendor:tetexmodel:tetexscope:eqversion:1.0.7

Trust: 0.3

vendor:tetexmodel:tetexscope:eqversion:1.0.6

Trust: 0.3

vendor:susemodel:linux enterprise serverscope:eqversion:8

Trust: 0.3

vendor:susemodel:linux enterprise serverscope:eqversion:9

Trust: 0.3

vendor:susemodel:linux desktopscope:eqversion:1.0

Trust: 0.3

vendor:sunmodel:solaris 9 x86 updatescope:eqversion:2

Trust: 0.3

vendor:sunmodel:solaris 9 x86scope: - version: -

Trust: 0.3

vendor:sunmodel:solarisscope:eqversion:9

Trust: 0.3

vendor:sunmodel:solaris 8 x86scope: - version: -

Trust: 0.3

vendor:sunmodel:solaris 8 sparcscope: - version: -

Trust: 0.3

vendor:sunmodel:solaris 7.0 x86scope: - version: -

Trust: 0.3

vendor:sunmodel:solarisscope:eqversion:7.0

Trust: 0.3

vendor:sunmodel:solaris 10 x86scope: - version: -

Trust: 0.3

vendor:sunmodel:solaris 10.0 x86scope: - version: -

Trust: 0.3

vendor:sunmodel:solarisscope:eqversion:10

Trust: 0.3

vendor:sgimodel:propackscope:eqversion:3.0

Trust: 0.3

vendor:scomodel:unixwarescope:eqversion:7.1.4

Trust: 0.3

vendor:s u s emodel:linux personalscope:eqversion:9.1

Trust: 0.3

vendor:s u s emodel:linux personalscope:eqversion:9.0

Trust: 0.3

vendor:s u s emodel:linux personalscope:eqversion:8.2

Trust: 0.3

vendor:redhatmodel:fedora core2scope: - version: -

Trust: 0.3

vendor:redhatmodel:enterprise linux wsscope:eqversion:3

Trust: 0.3

vendor:redhatmodel:enterprise linux ws ia64scope:eqversion:2.1

Trust: 0.3

vendor:redhatmodel:enterprise linux wsscope:eqversion:2.1

Trust: 0.3

vendor:redhatmodel:enterprise linux esscope:eqversion:3

Trust: 0.3

vendor:redhatmodel:enterprise linux es ia64scope:eqversion:2.1

Trust: 0.3

vendor:redhatmodel:enterprise linux esscope:eqversion:2.1

Trust: 0.3

vendor:redhatmodel:enterprise linux asscope:eqversion:3

Trust: 0.3

vendor:redhatmodel:enterprise linux as ia64scope:eqversion:2.1

Trust: 0.3

vendor:redhatmodel:enterprise linux asscope:eqversion:2.1

Trust: 0.3

vendor:redhatmodel:desktopscope:eqversion:3.0

Trust: 0.3

vendor:redhatmodel:advanced workstation for the itanium processor ia64scope:eqversion:2.1

Trust: 0.3

vendor:redhatmodel:advanced workstation for the itanium processorscope:eqversion:2.1

Trust: 0.3

vendor:mandrivamodel:linux mandrake amd64scope:eqversion:10.0

Trust: 0.3

vendor:mandrivamodel:linux mandrakescope:eqversion:10.0

Trust: 0.3

vendor:mandrakesoftmodel:corporate server x86 64scope:eqversion:3.0

Trust: 0.3

vendor:mandrakesoftmodel:corporate serverscope:eqversion:3.0

Trust: 0.3

vendor:libtiffmodel:do not usescope: - version: -

Trust: 0.3

vendor:avayamodel:modular messagingscope:eqversion:2.0

Trust: 0.3

vendor:avayamodel:modular messagingscope:eqversion:1.1

Trust: 0.3

vendor:avayamodel:modular messaging s3400scope: - version: -

Trust: 0.3

vendor:avayamodel:mn100scope: - version: -

Trust: 0.3

vendor:avayamodel:intuity lxscope: - version: -

Trust: 0.3

vendor:avayamodel:integrated managementscope: - version: -

Trust: 0.3

vendor:avayamodel:cvlanscope: - version: -

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.3.6

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.3.5

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.3.4

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.3.3

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.3.2

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.3.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.3

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.8

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.7

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.6

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.5

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.4

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.3

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.2

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.6

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.8

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.7

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.6

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2

Trust: 0.3

vendor:pdflibmodel:pdf library p1scope:neversion:5.0.4

Trust: 0.3

vendor:kdemodel:kdescope:neversion:3.3.2

Trust: 0.3

sources: CERT/CC: VU#354486 // CERT/CC: VU#258390 // CERT/CC: VU#356070 // CERT/CC: VU#539110 // CERT/CC: VU#706838 // CERT/CC: VU#331694 // CERT/CC: VU#687568 // CERT/CC: VU#687568 // BID: 11406 // JVNDB: JVNDB-2004-000445 // CNNVD: CNNVD-200501-308 // NVD: CVE-2004-0886

CVSS

SEVERITY

CVSSV2

CVSSV3

CARNEGIE MELLON: VU#687568
value: 10.33

Trust: 1.6

nvd@nist.gov: CVE-2004-0886
value: MEDIUM

Trust: 1.0

CARNEGIE MELLON: VU#354486
value: 10.69

Trust: 0.8

CARNEGIE MELLON: VU#258390
value: 2.03

Trust: 0.8

CARNEGIE MELLON: VU#356070
value: 22.31

Trust: 0.8

CARNEGIE MELLON: VU#539110
value: 5.04

Trust: 0.8

CARNEGIE MELLON: VU#706838
value: 9.38

Trust: 0.8

CARNEGIE MELLON: VU#331694
value: 15.94

Trust: 0.8

NVD: CVE-2004-0886
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200501-308
value: MEDIUM

Trust: 0.6

VULHUB: VHN-9316
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2004-0886
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-9316
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CERT/CC: VU#354486 // CERT/CC: VU#258390 // CERT/CC: VU#356070 // CERT/CC: VU#539110 // CERT/CC: VU#706838 // CERT/CC: VU#331694 // CERT/CC: VU#687568 // CERT/CC: VU#687568 // VULHUB: VHN-9316 // JVNDB: JVNDB-2004-000445 // CNNVD: CNNVD-200501-308 // NVD: CVE-2004-0886

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2004-0886

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200501-308

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-200501-308

CONFIGURATIONS

sources: JVNDB: JVNDB-2004-000445

PATCH

title:libtiffurl:http://www.miraclelinux.com/support/update/data/libtiff.html

Trust: 0.8

title:AXSA-2005-62:1url:http://www.miraclelinux.com/support/update/list.php?errata_id=184

Trust: 0.8

title:RHSA-2005:021url:https://rhn.redhat.com/errata/RHSA-2005-021.html

Trust: 0.8

title:RHSA-2005:354url:https://rhn.redhat.com/errata/RHSA-2005-354.html

Trust: 0.8

title:RHSA-2004:577url:http://rhn.redhat.com/errata/RHSA-2004-577.html

Trust: 0.8

title:101677url:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1

Trust: 0.8

title:101677url:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-3

Trust: 0.8

title:TLSA-2005-4url:http://www.turbolinux.com/security/2005/TLSA-2005-4.txt

Trust: 0.8

title:RHSA-2005:021url:http://www.jp.redhat.com/support/errata/RHSA/RHSA-2005-021J.html

Trust: 0.8

title:RHSA-2005:354url:http://www.jp.redhat.com/support/errata/RHSA/RHSA-2005-354J.html

Trust: 0.8

title:RHSA-2004:577url:http://www.jp.redhat.com/support/errata/RHSA/RHSA-2004-577J.html

Trust: 0.8

title:TLSA-2005-4url:http://www.turbolinux.co.jp/security/2005/TLSA-2005-4j.txt

Trust: 0.8

sources: JVNDB: JVNDB-2004-000445

EXTERNAL IDS

db:SECUNIAid:15227

Trust: 4.9

db:NVDid:CVE-2004-0886

Trust: 4.5

db:SECTRACKid:1011674

Trust: 3.5

db:SECUNIAid:12818

Trust: 3.5

db:CERT/CCid:VU#687568

Trust: 3.5

db:SECTRACKid:1012651

Trust: 2.4

db:BIDid:11406

Trust: 2.2

db:OSVDBid:10751

Trust: 1.6

db:CERT/CCid:VU#354486

Trust: 0.8

db:CERT/CCid:VU#258390

Trust: 0.8

db:OSVDBid:16084

Trust: 0.8

db:BIDid:13502

Trust: 0.8

db:CERT/CCid:VU#356070

Trust: 0.8

db:SECUNIAid:13607

Trust: 0.8

db:CERT/CCid:VU#539110

Trust: 0.8

db:OSVDBid:16085

Trust: 0.8

db:SECTRACKid:1013887

Trust: 0.8

db:CERT/CCid:VU#706838

Trust: 0.8

db:OSVDBid:16075

Trust: 0.8

db:XFid:20376

Trust: 0.8

db:CERT/CCid:VU#331694

Trust: 0.8

db:XFid:17715

Trust: 0.8

db:JVNDBid:JVNDB-2004-000445

Trust: 0.8

db:CNNVDid:CNNVD-200501-308

Trust: 0.7

db:BIDid:11501

Trust: 0.6

db:SUSEid:SUSE-SA:2004:039

Trust: 0.6

db:XFid:17819

Trust: 0.6

db:GENTOOid:GLSA-200410-30

Trust: 0.6

db:GENTOOid:GLSA-200410-20

Trust: 0.6

db:MANDRAKEid:MDKSA-2004:113

Trust: 0.6

db:VULHUBid:VHN-9316

Trust: 0.1

db:PACKETSTORMid:37530

Trust: 0.1

db:PACKETSTORMid:34737

Trust: 0.1

sources: CERT/CC: VU#354486 // CERT/CC: VU#258390 // CERT/CC: VU#356070 // CERT/CC: VU#539110 // CERT/CC: VU#706838 // CERT/CC: VU#331694 // CERT/CC: VU#687568 // CERT/CC: VU#687568 // VULHUB: VHN-9316 // BID: 11406 // JVNDB: JVNDB-2004-000445 // PACKETSTORM: 37530 // PACKETSTORM: 34737 // CNNVD: CNNVD-200501-308 // NVD: CVE-2004-0886

REFERENCES

url:http://secunia.com/advisories/15227/

Trust: 4.9

url:http://docs.info.apple.com/article.html?artnum=301528

Trust: 4.1

url:http://www.ciac.org/ciac/bulletins/p-015.shtml

Trust: 2.7

url:http://securitytracker.com/alerts/2004/dec/1012651.html

Trust: 2.4

url:http://www.idefense.com/application/poi/display?id=173&type=vulnerabilities

Trust: 2.4

url:http://secunia.com/advisories/12818/

Trust: 2.4

url:http://www.securityfocus.com/bid/11406

Trust: 1.9

url:http://www.kb.cert.org/vuls/id/687568

Trust: 1.9

url:http://securitytracker.com/id?1011674

Trust: 1.9

url:http://securitytracker.com/alerts/2004/oct/1011674.html

Trust: 1.6

url:http://seclists.org/lists/bugtraq/2004/oct/0135.html

Trust: 1.6

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=can-2004-0886

Trust: 1.6

url:http://www.osvdb.org/displayvuln.php?osvdb_id=10751

Trust: 1.6

url:http://sunsolve.sun.com/search/document.do?assetkey=1-66-201072-1

Trust: 1.4

url:http://www.kde.org/info/security/advisory-20041209-2.txt

Trust: 1.1

url:http://www.debian.org/security/2004/dsa-567

Trust: 1.1

url:http://www.mandriva.com/security/advisories?name=mdksa-2004:109

Trust: 1.1

url:http://www.mandriva.com/security/advisories?name=mdksa-2005:052

Trust: 1.1

url:https://oval.cisecurity.org/repository/search/definition/oval%3aorg.mitre.oval%3adef%3a100116

Trust: 1.1

url:https://oval.cisecurity.org/repository/search/definition/oval%3aorg.mitre.oval%3adef%3a9907

Trust: 1.1

url:http://www.redhat.com/support/errata/rhsa-2004-577.html

Trust: 1.1

url:http://www.redhat.com/support/errata/rhsa-2005-021.html

Trust: 1.1

url:http://www.redhat.com/support/errata/rhsa-2005-354.html

Trust: 1.1

url:http://secunia.com/advisories/12818

Trust: 1.1

url:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1

Trust: 1.1

url:http://www.novell.com/linux/security/advisories/2004_38_libtiff.html

Trust: 1.1

url:http://www.trustix.org/errata/2004/0054/

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/17715

Trust: 1.1

url:http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000888

Trust: 1.0

url:http://marc.info/?l=bugtraq&m=109779465621929&w=2

Trust: 1.0

url:http://remahl.se/david/vuln/011/

Trust: 0.9

url:http://secunia.com/advisories/13607/

Trust: 0.9

url:http://www.idefense.com/application/poi/display?id=239

Trust: 0.8

url:http://www.digitalmunition.com/dma%5b2005-0502a%5d.txt

Trust: 0.8

url:http://www.securityfocus.com/bid/13502/

Trust: 0.8

url:http://www.osvdb.org/displayvuln.php?osvdb_id=16084

Trust: 0.8

url:http://www.idefense.com/application/poi/display?id=240&type=vulnerabilities

Trust: 0.8

url:http://www.securityfocus.org/bid/13488

Trust: 0.8

url:http://www.securitytracker.com/alerts/2005/may/1013887.html

Trust: 0.8

url:http://www.osvdb.org/displayvuln.php?osvdb_id=16085

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/20376

Trust: 0.8

url:http://www.apple.com/server/macosx/

Trust: 0.8

url:http://www.osvdb.org/16075

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2004-0886

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/17715

Trust: 0.8

url:http://jvn.jp/cert/jvnvu%23687568

Trust: 0.8

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2004-0886

Trust: 0.8

url:http://www.gentoo.org/security/en/glsa/glsa-200410-20.xml

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/17819

Trust: 0.6

url:http://www.gentoo.org/security/en/glsa/glsa-200410-30.xml

Trust: 0.6

url:http://www.securityfocus.com/bid/11501

Trust: 0.6

url:http://www.mandriva.com/security/advisories?name=mdksa-2004:113

Trust: 0.6

url:http://marc.theaimsgroup.com/?l=bugtraq&m=109880927526773&w=2

Trust: 0.6

url:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57769-1

Trust: 0.3

url:http://www.libtiff.org/

Trust: 0.3

url:http://rhn.redhat.com/errata/rhsa-2004-577.html

Trust: 0.3

url:http://rhn.redhat.com/errata/rhsa-2005-021.html

Trust: 0.3

url:http://rhn.redhat.com/errata/rhsa-2005-354.html

Trust: 0.3

url:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1&searchclause=

Trust: 0.3

url:http://support.avaya.com/elmodocs2/security/asa-2005-002_rhsa-2004-577.pdf

Trust: 0.3

url:/archive/1/378421

Trust: 0.3

url:http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000888

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=109779465621929&amp;w=2

Trust: 0.1

url:http://www.apple.com/support/downloads/securityupdate2005005server.html

Trust: 0.1

url:http://www.digitalmunition.com/dma[2005-0502a].txt

Trust: 0.1

url:http://remahl.se/david/vuln/010/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://remahl.se/david/vuln/012/

Trust: 0.1

url:http://remahl.se/david/vuln/004/

Trust: 0.1

url:http://www.apple.com/support/downloads/securityupdate2005005client.html

Trust: 0.1

url:http://secunia.com/about_secunia_advisories/

Trust: 0.1

url:http://secunia.com/secunia_vacancies/

Trust: 0.1

url:http://www.idefense.com/application/poi/display?id=239&type=vulnerabilities

Trust: 0.1

url:http://secunia.com/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/advisories/14188/

Trust: 0.1

url:http://secunia.com/advisories/12549/

Trust: 0.1

url:http://secunia.com/product/96/

Trust: 0.1

url:http://secunia.com/advisories/13199/

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_s390.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_i386.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_alpha.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_hppa.deb

Trust: 0.1

url:http://www.debian.org/security/faq

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_hppa.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_alpha.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_mipsel.deb

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2004-0803

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_ia64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_powerpc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_hppa.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_sparc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/tiff_3.5.5-6woody1.dsc

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_arm.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_mips.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_mipsel.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_s390.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_ia64.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_i386.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_mips.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_mipsel.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_mips.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_m68k.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/tiff_3.5.5-6woody1.diff.gz

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_powerpc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_powerpc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_arm.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_i386.deb

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2004-0804

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/tiff_3.5.5.orig.tar.gz

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_ia64.deb

Trust: 0.1

url:http://packages.debian.org/<pkg>

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_s390.deb

Trust: 0.1

url:http://security.debian.org/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2004-0886

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_sparc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_m68k.deb

Trust: 0.1

url:http://www.debian.org/security/

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g_3.5.5-6woody1_alpha.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_arm.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5.5-6woody1_sparc.deb

Trust: 0.1

url:http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5.5-6woody1_m68k.deb

Trust: 0.1

sources: CERT/CC: VU#354486 // CERT/CC: VU#258390 // CERT/CC: VU#356070 // CERT/CC: VU#539110 // CERT/CC: VU#706838 // CERT/CC: VU#331694 // CERT/CC: VU#687568 // CERT/CC: VU#687568 // VULHUB: VHN-9316 // BID: 11406 // JVNDB: JVNDB-2004-000445 // PACKETSTORM: 37530 // PACKETSTORM: 34737 // CNNVD: CNNVD-200501-308 // NVD: CVE-2004-0886

CREDITS

chris chris@cr-secure.net

Trust: 0.6

sources: CNNVD: CNNVD-200501-308

SOURCES

db:CERT/CCid:VU#354486
db:CERT/CCid:VU#258390
db:CERT/CCid:VU#356070
db:CERT/CCid:VU#539110
db:CERT/CCid:VU#706838
db:CERT/CCid:VU#331694
db:CERT/CCid:VU#687568
db:CERT/CCid:VU#687568
db:VULHUBid:VHN-9316
db:BIDid:11406
db:JVNDBid:JVNDB-2004-000445
db:PACKETSTORMid:37530
db:PACKETSTORMid:34737
db:CNNVDid:CNNVD-200501-308
db:NVDid:CVE-2004-0886

LAST UPDATE DATE

2024-11-20T19:28:26.641000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#354486date:2005-05-17T00:00:00
db:CERT/CCid:VU#258390date:2005-05-16T00:00:00
db:CERT/CCid:VU#356070date:2005-05-16T00:00:00
db:CERT/CCid:VU#539110date:2005-08-23T00:00:00
db:CERT/CCid:VU#706838date:2005-05-24T00:00:00
db:CERT/CCid:VU#331694date:2005-05-25T00:00:00
db:CERT/CCid:VU#687568date:2005-01-25T00:00:00
db:CERT/CCid:VU#687568date:2005-01-25T00:00:00
db:VULHUBid:VHN-9316date:2017-10-11T00:00:00
db:BIDid:11406date:2009-05-05T15:46:00
db:JVNDBid:JVNDB-2004-000445date:2007-04-01T00:00:00
db:CNNVDid:CNNVD-200501-308date:2009-02-05T00:00:00
db:NVDid:CVE-2004-0886date:2017-10-11T01:29:36.420

SOURCES RELEASE DATE

db:CERT/CCid:VU#354486date:2005-05-16T00:00:00
db:CERT/CCid:VU#258390date:2005-05-09T00:00:00
db:CERT/CCid:VU#356070date:2005-05-06T00:00:00
db:CERT/CCid:VU#539110date:2005-01-20T00:00:00
db:CERT/CCid:VU#706838date:2005-05-16T00:00:00
db:CERT/CCid:VU#331694date:2005-05-16T00:00:00
db:CERT/CCid:VU#687568date:2004-12-01T00:00:00
db:CERT/CCid:VU#687568date:2004-12-01T00:00:00
db:VULHUBid:VHN-9316date:2005-01-27T00:00:00
db:BIDid:11406date:2004-10-13T00:00:00
db:JVNDBid:JVNDB-2004-000445date:2007-04-01T00:00:00
db:PACKETSTORMid:37530date:2005-05-29T20:22:44
db:PACKETSTORMid:34737date:2004-10-26T02:30:56
db:CNNVDid:CNNVD-200501-308date:2004-10-14T00:00:00
db:NVDid:CVE-2004-0886date:2005-01-27T05:00:00