Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Ubuntu 12.10: 1631-2 Urgent: LibPNG Vulnerability Exploit

ubuntu
Calendar Grey November 15, 2012
Scroller Ubuntu
A critical vulnerability concerning Ubuntu arises from LibTIFF's processing of corrupted images, potentially leading to system crashes or unauthorized code execution.
LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.

Summary

LibTIFF could be made to crash or run programs as your login if it opened a

specially crafted file.

Software Description:

- tiff: Tag Image File Format (TIFF) library

Details:

It was discovered that LibTIFF incorrectly handled certain malformed images

using the PixarLog compression format. If a user or automated system were

tricked into opening a specially crafted TIFF image, a remote attacker

could crash the application, leading to a denial of service, or possibly

execute arbitrary code with user privileges. (CVE-2012-4447)

Huzaifa S. Sidhpurwala discovered that the ppm2tiff tool incorrectly

handled certain malformed PPM images. If a user or automated system were

tricked into opening a specially crafted PPM image, a remote attacker could

crash the application, leading to a denial of service, or possibly execute

arbitrary code with user privileges. (CVE-2012-4564)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  libtiff5                        4.0.2-1ubuntu2.1

Ubuntu 12.04 LTS:
  libtiff4                        3.9.5-2ubuntu1.3

Ubuntu 11.10:
  libtiff4                        3.9.5-1ubuntu1.4

Ubuntu 10.04 LTS:
  libtiff4                        3.9.2-2ubuntu0.11

Ubuntu 8.04 LTS:
  libtiff4                        3.8.2-7ubuntu3.14

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1631-1

CVE-2012-4447, CVE-2012-4564

Severity
critical
Lowest
Low
Medium
High
Critical

November 15, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.