Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 14.04 LTS: USN-2205-2 Security: LibTIFF Image Vulnerabilities

ubuntu
Calendar Grey May 6, 2014
Scroller Ubuntu
Recent weaknesses in LibTIFF for Ubuntu might allow application failures or unauthorized execution of code via specially designed image files.
LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.

Summary

LibTIFF could be made to crash or run programs as your login if it opened a

specially crafted file.

Software Description:

- tiff: Tag Image File Format (TIFF) library

Details:

Pedro Ribeiro discovered that LibTIFF incorrectly handled certain

malformed images when using the gif2tiff tool. If a user or automated

system were tricked into opening a specially crafted GIF image, a remote

attacker could crash the application, leading to a denial of service, or

possibly execute arbitrary code with user privileges. This issue only

affected Ubuntu 10.04 LTS, Ubunu 12.04 LTS, Ubuntu 12.10 and Ubuntu 13.10.

(CVE-2013-4231)

Pedro Ribeiro discovered that LibTIFF incorrectly handled certain

malformed images when using the tiff2pdf tool. If a user or automated

system were tricked into opening a specially crafted TIFF image, a remote

attacker could crash the application, leading to a denial of service, or

possibly execute arbitrary code with user privileges. This issue only

...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  libtiff5                        4.0.3-7ubuntu0.1

Ubuntu 13.10:
  libtiff5                        4.0.2-4ubuntu3.1

Ubuntu 12.10:
  libtiff5                        4.0.2-1ubuntu2.3

Ubuntu 12.04 LTS:
  libtiff4                        3.9.5-2ubuntu1.6

Ubuntu 10.04 LTS:
  libtiff4                        3.9.2-2ubuntu0.14

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2205-1

CVE-2013-4231, CVE-2013-4232, CVE-2013-4243, CVE-2013-4244

Severity
important
Lowest
Low
Medium
High
Critical

May 06, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.