This allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF Internet Fax image file that has been compressed using CCITT Group 4 encoding, related to the EXPAND2D macro in libtiff/tif_fax3.h. NOTE: some of these details are obtained from third party information.
Vulnerable Systems:
* Symantec Clientless VPN Gateway 4400 Series 4.0 SP3
* Symantec Clientless VPN Gateway 4400 Series 4.0 SP2
* Symantec Clientless VPN Gateway 4400 Series 4.0 SP1
libTIFF is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Vendor Status:
Symantec as issued an update for this vulnerablity