Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian Squeeze: DSA-2575-1 Moderate: tiff Heap Overflow

debian
Calendar Grey November 18, 2012
Debian Logo
Update tiff libraries since Debian DSA-2575-1 fixes a heap overflow vulnerability, enabling potential execution of arbitrary code by attackers.
It was discovered that ppm2tiff of the tiff tools, a set of utilities for TIFF manipulation and conversion, is not properly checking the return value of an internal function used i...

Summary

It was discovered that ppm2tiff of the tiff tools, a set of utilities
for TIFF manipulation and conversion, is not properly checking the return
value of an internal function used in order to detect integer overflows.
As a consequence, ppm2tiff suffers of a heap-based buffer overflow.
This allows attacker to potentially execute arbitrary code via a crafted
ppm image, especially in scenarios in which images are automatically
processed.

For the stable distribution (squeeze), this problem has been fixed in
version 3.9.4-5+squeeze7.

For the testing distribution (wheezy), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in
version 4.0.2-5.

We recommend that you upgrade your tiff packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: tiff
CVE ID: CVE-2012-4564

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here