Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Ubuntu 14.04 LTS: USN-2205-2 Security: LibTIFF Image Vulnerabilities

Ubuntu Large Esm H500
LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.
=========================================================================Ubuntu Security Notice USN-2205-1
May 06, 2014

tiff vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS
- Ubuntu 13.10
- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

LibTIFF could be made to crash or run programs as your login if it opened a
specially crafted file.

Software Description:
- tiff: Tag Image File Format (TIFF) library

Details:

Pedro Ribeiro discovered that LibTIFF incorrectly handled certain
malformed images when using the gif2tiff tool. If a user or automated
system were tricked into opening a specially crafted GIF image, a remote
attacker could crash the application, leading to a denial of service, or
possibly execute arbitrary code with user privileges. This issue only
affected Ubuntu 10.04 LTS, Ubunu 12.04 LTS, Ubuntu 12.10 and Ubuntu 13.10.
(CVE-2013-4231)

Pedro Ribeiro discovered that LibTIFF incorrectly handled certain
malformed images when using the tiff2pdf tool. If a user or automated
system were tricked into opening a specially crafted TIFF image, a remote
attacker could crash the application, leading to a denial of service, or
possibly execute arbitrary code with user privileges. This issue only
affected Ubuntu 10.04 LTS, Ubunu 12.04 LTS, Ubuntu 12.10 and Ubuntu 13.10.
(CVE-2013-4232)

Murray McAllister discovered that LibTIFF incorrectly handled certain
malformed images when using the gif2tiff tool. If a user or automated
system were tricked into opening a specially crafted GIF image, a remote
attacker could crash the application, leading to a denial of service, or
possibly execute arbitrary code with user privileges. (CVE-2013-4243)

Huzaifa Sidhpurwala discovered that LibTIFF incorrectly handled certain
malformed images when using the gif2tiff tool. If a user or automated
system were tricked into opening a specially crafted GIF image, a remote
attacker could crash the application, leading to a denial of service, or
possibly execute arbitrary code with user privileges. This issue only
affected Ubuntu 10.04 LTS, Ubunu 12.04 LTS, Ubuntu 12.10 and Ubuntu 13.10.
(CVE-2013-4244)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  libtiff5                        4.0.3-7ubuntu0.1

Ubuntu 13.10:
  libtiff5                        4.0.2-4ubuntu3.1

Ubuntu 12.10:
  libtiff5                        4.0.2-1ubuntu2.3

Ubuntu 12.04 LTS:
  libtiff4                        3.9.5-2ubuntu1.6

Ubuntu 10.04 LTS:
  libtiff4                        3.9.2-2ubuntu0.14

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2205-1
  CVE-2013-4231, CVE-2013-4232, CVE-2013-4243, CVE-2013-4244

Package Information:
  https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.1
  https://launchpad.net/ubuntu/+source/tiff/4.0.2-4ubuntu3.1
  https://launchpad.net/ubuntu/+source/tiff/4.0.2-1ubuntu2.3
  https://launchpad.net/ubuntu/+source/tiff/3.9.5-2ubuntu1.6
  https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.14


Ubuntu 14.04 LTS: USN-2205-2 Security: LibTIFF Image Vulnerabilities

ubuntu
Calendar Grey May 6, 2014
Dist Ubuntu Esm H88
Recent weaknesses in LibTIFF for Ubuntu might allow application failures or unauthorized execution of code via specially designed image files.
LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: libtiff5 4.0.3-7ubuntu0.1 Ubuntu 13.10: libtiff5 4.0.2-4ubuntu3.1 Ubuntu 12.10: libtiff5 4.0.2-1ubuntu2.3 Ubuntu 12.04 LTS: libtiff4 3.9.5-2ubuntu1.6 Ubuntu 10.04 LTS: libtiff4 3.9.2-2ubuntu0.14 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2205-1

CVE-2013-4231, CVE-2013-4232, CVE-2013-4243, CVE-2013-4244

Severity
important
Lowest
Low
Medium
High
Critical

May 06, 2014

Package Information

https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.1 https://launchpad.net/ubuntu/+source/tiff/4.0.2-4ubuntu3.1 https://launchpad.net/ubuntu/+source/tiff/4.0.2-1ubuntu2.3 https://launchpad.net/ubuntu/+source/tiff/3.9.5-2ubuntu1.6 https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.14

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here