Fedora Account System
Red Hat Associate
Red Hat Customer
Dmitry V. Levin has reported to vendor-sec an issue with tiffdump. The issue appears to be an integer overflow which could lead to a buffer overflow. There is no patch yet. More work is being done on this issue. I'll post more information when it's available. This issue should also affect FC2
Created attachment 109026 [details] Demo exploit image.
Removing embargo
Does this bugzilla entry relate to CVE CAN=2004-1183? Has this issue been fixed by Fedora Update Notification FEDORA-2005-597 <http://www.redhat.com/archives/fedora-announce-list/2005-January/msg00023.html> and FEDORA-2005-598 <http://www.redhat.com/archives/fedora-announce-list/2005-January/msg00024.html? ??
Yes it does. If you look closely, the changelog mentions this bug.