Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 2: FEDORA-2004-334 Critical: LibTiff Integer and Buffer Overflows

fedora
Calendar Grey October 14, 2004
Dist Fedora Esm H88
Integer and buffer overflow vulnerabilities identified in libtiff; Fedora users are urged to update to enhance system security.
Chris Evans discovered a number of integer overflow bugs that affect libtiff

Summary

The libtiff package contains a library of functions for manipulating

TIFF (Tagged Image File Format) image format files. TIFF is a widely

used file format for bitmapped images. TIFF files usually end in the

.tif extension and they are often quite large.

The libtiff package should be installed if you need to manipulate TIFF

format image files.

Update Information:

The libtiff package contains a library of functions for manipulating TIFF (Tagged Image File Format) image format files. TIFF is a widely used file format for bitmapped images.

During a source code audit, Chris Evans discovered a number of integer overflow bugs that affect libtiff. An attacker who has the ability to trick a user into opening a malicious TIFF file could cause the application linked to libtiff to crash or possibly execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0886 to this issue.

Additionally, a number of buffer overflow bugs that affect libtiff have been found. An attacker who has the ability to trick a user into opening a malicious TIFF file could cause the application linked to libtiff to crash or possibly execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0803 to this issue.

All users are advised to up...

Read the Full Advisory

Change Log

References

Fedora Update Notification FEDORA-2004-334 2004-10-14
Product : Fedora Core 2 Name : libtiff Version : 3.5.7 Release : 20.2 Summary : A library of functions for manipulating TIFF format image files. Description : The libtiff package contains a library of functions for manipulating TIFF (Tagged Image File Format) image format files. TIFF is a widely used file format for bitmapped images. TIFF files usually end in the .tif extension and they are often quite large.
The libtiff package should be installed if you need to manipulate TIFF format image files.

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora Core 2
Name: libtiff
Version: 3.5.7
Release: 20.2
Summary: A library of functions for manipulating TIFF format image

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here