Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian: DSA-2552-1 Moderate: TIFF Denial Of Service And Escalation Threat

debian
Calendar Grey September 26, 2012
Debian Logo
Urgent TIFF security patch in Debian addresses multiple vulnerabilities. Update immediately to avoid possible attacks through manipulated images.
Several vulnerabilities were discovered in Tiff, a library set and tools to support the Tag Image File Format (TIFF), allowing denial of service and potential privilege escalation

Summary

These vulnerabilities can be exploited via a specially crafted TIFF image.

CVE-2012-2113
The tiff2pdf utility has an integer overflow error when parsing images.

CVE-2012-3401
Huzaifa Sidhpurwala discovered heap-based buffer overflow in the
t2p_read_tiff_init() function.

CVE-2010-2482
An invalid td_stripbytecount field is not properly handle and can trigger a
NULL pointer dereference.

CVE-2010-2595
An array index error, related to "downsampled OJPEG input." in the
TIFFYCbCrtoRGB function causes an unexpected crash.

CVE-2010-2597
Also related to "downsampled OJPEG input", the TIFFVStripSize function crash
unexpectly.

CVE-2010-2630
The TIFFReadDirectory function does not properly validate the data types of
codec-specific tags that have an out-of-order position in a TIFF file.

CVE-2010-4665
The tiffdump utility has an integer overflow in the ReadDirectory function.

For the stable distribution (squeeze), these problems have been fixed in
version 3.9.4-5+squeeze5.

For the testing dist...

Read the Full Advisory

Package: tiff
CVE ID: CVE-2010-2482 CVE-2010-2595 CVE-2010-2597 CVE-2010-2630

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here