Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SciLinux: CVE-2009-5022 Important: libtiff Buffer Overflow

Scientific Large Esm H500
Important: libtiff security update
Date: Mon, 18 Apr 2011 14:36:14 -0500
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: Security ERRATA Important: libtiff on SL6.x i386/x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 
MIME-Version: 1.0

Synopsis:	Important: libtiff security update
Issue date:	2011-04-18
CVE Names:	CVE-2009-5022

A heap-based buffer overflow flaw was found in the way libtiff processed
certain TIFF image files that were compressed with the JPEG compression
algorithm. An attacker could use this flaw to create a specially-crafted
TIFF file that, when opened, would cause an application linked against
libtiff to crash or, possibly, execute arbitrary code. (CVE-2009-5022)

All running applications linked against libtiff must be restarted for
this update to take effect.

SL 6.x

 SRPMS:
libtiff-3.9.4-1.el6_0.3.src.rpm
 i386:
libtiff-3.9.4-1.el6_0.3.i686.rpm
libtiff-devel-3.9.4-1.el6_0.3.i686.rpm
libtiff-static-3.9.4-1.el6_0.3.i686.rpm
 x86_64:
libtiff-3.9.4-1.el6_0.3.i686.rpm
libtiff-3.9.4-1.el6_0.3.x86_64.rpm
libtiff-devel-3.9.4-1.el6_0.3.i686.rpm
libtiff-devel-3.9.4-1.el6_0.3.x86_64.rpm
libtiff-static-3.9.4-1.el6_0.3.x86_64.rpm

- Scientific Linux Development Team
Your message here