Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The recent tiff update DSA-2210-1 introduced a regression that could
lead to encoding problems of tiff files. This update fixes this problem (bug
#630042).
For reference, the description of the original DSA, which fixed
CVE-2011-0191 CVE-2011-0192 CVE-2011-1167
CVE-2011-0191
A buffer overflow allows to execute arbitrary code or cause
a denial of service via a crafted TIFF image with JPEG encoding.
This issue affects the Debian 5.0 Lenny package only.
CVE-2011-0192
A buffer overflow allows to execute arbitrary code or cause
a denial of service via a crafted TIFF Internet Fax image
file that has been compressed using CCITT Group 4 encoding.
CVE-2011-1167
Heap-based buffer overflow in the thunder (aka ThunderScan)
decoder allows to execute arbitrary code via a TIFF file that
has an unexpected BitsPerSample value.
For the oldstable distribution (lenny), this problem has been fixed in
version 3.8.2-11.5.
For the stable distribution (squeeze), this problem has been fixed in
version 3.9.4-5...
Get the latest Linux and open source security news straight to your inbox.