Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 11.10-8.04 LTS USN-1416-1 Moderate: TIFF Remote Execution Risk

ubuntu
Calendar Grey April 4, 2012
Scroller Ubuntu
Potential flaws in TIFF libraries may permit crashes or arbitrary code execution upon opening specially crafted images. Immediate update is recommended.
The TIFF library could be made to crash or run programs as your login if it opened a specially crafted file.

Summary

The TIFF library could be made to crash or run programs as your login if it

opened a specially crafted file.

Software Description:

- tiff: Tag Image File Format (TIFF) library

Details:

Alexander Gavrun discovered that the TIFF library incorrectly allocated

space for a tile. If a user or automated system were tricked into opening a

specially crafted TIFF image, a remote attacker could execute arbitrary

code with user privileges, or crash the application, leading to a denial of

service. (CVE-2012-1173)

It was discovered that the tiffdump utility incorrectly handled directory

data structures with many directory entries. If a user or automated system

were tricked into opening a specially crafted TIFF image, a remote attacker

could crash the application, leading to a denial of service, or possibly

execute arbitrary code with user privileges. This issue only applied to

Ubuntu 8.04 LTS, Ubuntu 10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04.

(CVE-2010-4665)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  libtiff4                        3.9.5-1ubuntu1.1

Ubuntu 11.04:
  libtiff4                        3.9.4-5ubuntu6.1

Ubuntu 10.10:
  libtiff4                        3.9.4-2ubuntu0.5

Ubuntu 10.04 LTS:
  libtiff4                        3.9.2-2ubuntu0.8

Ubuntu 8.04 LTS:
  libtiff4                        3.8.2-7ubuntu3.10

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1416-1

CVE-2010-4665, CVE-2012-1173

April 04, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.