Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Debian 7 Wheezy DSA-2965-1 Moderate: gif2tiff Code Execution Risk

debian
Calendar Grey June 22, 2014
Scroller Debian
Debian's security announcement DSA-2965-1 reveals a serious vulnerability in gif2tiff, exposed to a heap overflow that may enable arbitrary code execution
Murray McAllister discovered a heap-based buffer overflow in the gif2tiff command line tool

Summary

For the stable distribution (wheezy), this problem has been fixed in
version 4.0.2-6+deb7u3.

For the testing distribution (jessie), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in
version 4.0.3-9.

We recommend that you upgrade your tiff packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Package: tiff
CVE ID: CVE-2013-4243

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.