==========================================================Ubuntu Security Notice USN-801-1              July 13, 2009
tiff vulnerability
CVE-2009-2347
==========================================================
A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
  libtiff4                        3.7.4-1ubuntu3.6

Ubuntu 8.04 LTS:
  libtiff4                        3.8.2-7ubuntu3.4

Ubuntu 8.10:
  libtiff4                        3.8.2-11ubuntu0.8.10.3

Ubuntu 9.04:
  libtiff4                        3.8.2-11ubuntu0.9.04.3

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

Tielei Wang and Tom Lane discovered that the TIFF library did not correctly
handle certain malformed TIFF images. If a user or automated system were
tricked into processing a malicious image, an attacker could execute
arbitrary code with the privileges of the user invoking the program.


Updated packages for Ubuntu 6.06 LTS:

  Source archives:

          Size/MD5:    21054 b184fc5a65469b42e7339ed36fcbd352
          Size/MD5:      764 5a34b751c2d11afb70070d2173891226
          Size/MD5:  1280113 02cf5c3820bda83b35bb35b45ae27005

  amd64 architecture (Athlon64, Opteron, EM64T Xeon):

          Size/MD5:   220964 32b03a7ff77bfc052f81ead1310ba61d
          Size/MD5:   282410 b7e639de426fd499ce7898ab5d22082d
          Size/MD5:   475680 9ae1232f31f5a56ed48d36523996b7ef
          Size/MD5:    44736 60343671d61e34c5937708dc3f64efda
          Size/MD5:    49912 26dd138e59ad8f287ce4e39ea04159e0

  i386 architecture (x86 compatible Intel/AMD):

          Size/MD5:   206140 9d5d67fb3830c0126ddfe56e7be8a78c
          Size/MD5:   259038 c4cd6b64f45de6c2387180bf0c029d64
          Size/MD5:   461908 b93598c6a241ed4dcc2ea9fd55eeb82f
          Size/MD5:    44704 7da9d28905050b7a436f20ef2417eb83
          Size/MD5:    49242 2f45bd92eb474e4f78cba91d45e9a2ec

  powerpc architecture (Apple Macintosh G3/G4/G5):

          Size/MD5:   239858 d721fc667879d1ef8f4e0f23c5ada2ea
          Size/MD5:   288108 f142f5e1d8856c927cd9705e67a1dfa7
          Size/MD5:   476004 e2b229ae0592a3a8ce273cffaf5b3c40
          Size/MD5:    46954 64dd6f32ba8a52094fdd37a7f82a9e07
          Size/MD5:    51588 488453ac8da21d2ca65822a39ff8a703

  sparc architecture (Sun SPARC/UltraSPARC):

          Size/MD5:   208814 982a4a1b64aeeadc5e7b0bc962990754
          Size/MD5:   270074 7135dfc15e5c4c691cd0902475815ba1
          Size/MD5:   466750 a61aa69f5e417585d6448d03270582de
          Size/MD5:    44656 06f194d15eed1792831306e39f983e6d
          Size/MD5:    49788 27a6b68bc6c95fa630f215f0ddf9a77b

Updated packages for Ubuntu 8.04 LTS:

  Source archives:

          Size/MD5:    19568 5bfb2cb6842497228bf9ac35340964c2
          Size/MD5:      860 439a48e1a2ff200bb5656e9674a001bc
          Size/MD5:  1333780 e6ec4ab957ef49d5aabc38b7a376910b

  amd64 architecture (Athlon64, Opteron, EM64T Xeon):

          Size/MD5:   186484 7d1ec8bbd94dc0e66d064716586c0b07
          Size/MD5:   570808 3ff13c20038ba528af352e55e2d6d1bc
          Size/MD5:   130788 aa56546b961c12c6d24cd52a4df380a7
          Size/MD5:     5076 00b209a590da754d7012caafea71a7cd
          Size/MD5:    10492 ea0e67a0e5fa1ed557455be73ae0a919

  i386 architecture (x86 compatible Intel/AMD):

          Size/MD5:   175322 acdeefa0cfe2c524098027f12af53c69
          Size/MD5:   552282 32c8f66f4749fc2a54be66e42f4edbd6
          Size/MD5:   122488 0d278f298f7c5ed6c4357b88218f6c32
          Size/MD5:     5044 89d1f18fc0e9b23bbb136707316e9392
          Size/MD5:     9934 b9316510bba0f91803c9e735da48e176

  lpia architecture (Low Power Intel Architecture):

          Size/MD5:   177040 3e71f1789624abbd10d1532c8f6ca38a
          Size/MD5:   554844 3cc1263bcb56cf9746716990a2ae8136
          Size/MD5:   123640 6c75304de5001fe2263d45cf788aabf0
          Size/MD5:     4916 1098e8a9fff0cbd1ae0820d62d2268f6
          Size/MD5:     9982 97ac08252336fa2d32439ab8ccc5578e

  powerpc architecture (Apple Macintosh G3/G4/G5):

          Size/MD5:   223464 5466be5e47908622c79d3ef14ac40f64
          Size/MD5:   576826 43e6e505da757ddcb637d2e5f5c90e55
          Size/MD5:   134100 5c09d9828d094ec8fd5c3119d0a833a3
          Size/MD5:     7510 6ca2d1d4c524e5115870adf6e494c6db
          Size/MD5:    13286 c0c749c9caf673a2d0f5b1cf93f9c0c2

  sparc architecture (Sun SPARC/UltraSPARC):

          Size/MD5:   178862 b46ce275aa291e14b580256de7f2d00d
          Size/MD5:   558208 6a5c431715bde6315033dc2639a7d007
          Size/MD5:   122246 128a30981124c2535cda616dbfa6ff1f
          Size/MD5:     4814 6374c4cad1d0106074e308514a668557
          Size/MD5:    10704 14a879255294ef774e6778848ac63954

Updated packages for Ubuntu 8.10:

  Source archives:

          Size/MD5:    39176 060a8ab7b01f6cf67746e2bdc8f9fede
          Size/MD5:     1328 4f1f59e4f8173b22b2b1fc5b75993d56
          Size/MD5:  1333780 e6ec4ab957ef49d5aabc38b7a376910b

  Architecture independent packages:

          Size/MD5:   334762 c06570f8ef3133f29215f3522b32000d

  amd64 architecture (Athlon64, Opteron, EM64T Xeon):

          Size/MD5:   250516 091e3d2f7dcdd470ebb60bd0985898b1
          Size/MD5:   134144 5cdfdbc0e599956a5cc39c93c3e766e0
          Size/MD5:     6282 e5184d8cabee9e62fe95c02dd5ceb42c
          Size/MD5:    11898 0f9cdc8d758e49247bca6aca38b76e29
          Size/MD5:   191614 c43454705f0e70af2c02274660e19fe1

  i386 architecture (x86 compatible Intel/AMD):

          Size/MD5:   233308 3a6665da1bd3d77c9e8bc89305d1bc88
          Size/MD5:   125952 7c515ac8b3281482eea7dcc0b3fc07d2
          Size/MD5:     6268 915e7137fa484b78bf4ab12eb8b020a3
          Size/MD5:    11232 08dc61532601140dceacd61301f3c157
          Size/MD5:   176244 3779c5312783f177bceef089f6d7c413

  lpia architecture (Low Power Intel Architecture):

          Size/MD5:   235792 8d83dd863f9392f20540777ffea6e973
          Size/MD5:   127646 0a3313ab87db8c462ec040eab933fd3c
          Size/MD5:     6132 e019a27add2bf0ad3dcc17351ba391bf
          Size/MD5:    11288 4d6ba5f06725040c5288edf43f848ea5
          Size/MD5:   178536 1f8bb64685cbcf23af9c493ef3fe3c50

  powerpc architecture (Apple Macintosh G3/G4/G5):

          Size/MD5:   256482 83002f03cd860be09b0c3f422b0cd303
          Size/MD5:   137238 0c56ea5382757b05719a14a54292344a
          Size/MD5:     8728 afa7813cf255183979211a6bbd49c34a
          Size/MD5:    14240 16314a49bc8b221ba0f4b33b221da280
          Size/MD5:   221282 7fc666a2e5b2fbff826327911d0ddb2c

  sparc architecture (Sun SPARC/UltraSPARC):

          Size/MD5:   237676 2d1d8633f7d524ab4da9ad3a86e86372
          Size/MD5:   124088 131aad61d078a6b62615f90abedc91c9
          Size/MD5:     6016 36855fafb32b6d9d5d04f87202c7fa49
          Size/MD5:    12050 99a62c3a0072c968696cbdce177619b2
          Size/MD5:   183806 1bdaeb372368abdc1d9dd98695b1d0da

Updated packages for Ubuntu 9.04:

  Source archives:

          Size/MD5:    39178 4bfb276aca2734298c06b0ed5de2a246
          Size/MD5:     1328 0c41ba9d08e1fe09c45eb5079a5ea137
          Size/MD5:  1333780 e6ec4ab957ef49d5aabc38b7a376910b

  Architecture independent packages:

          Size/MD5:   334774 1d7901d92961ad1c2ed2abb160774861

  amd64 architecture (Athlon64, Opteron, EM64T Xeon):

          Size/MD5:   191662 903599a6ede36e4fd1fe8eed3b04c604
          Size/MD5:   250586 891e5abb016617849d19ebb6f353900d
          Size/MD5:   134188 f63adbd5a185f439dbcbe06b0a95bf8d
          Size/MD5:     6282 470be440355d54b6af5dfddab3712524
          Size/MD5:    11900 19eab0f2ea2f0f429d0592e4f9215467

  i386 architecture (x86 compatible Intel/AMD):

          Size/MD5:   176262 5a64f79c12421333b2b2767e073d5a47
          Size/MD5:   233314 3eb4d2a53824a6f143b83ebf0f96383d
          Size/MD5:   126052 f3c7a181b29c9a4425b8e2450951b612
          Size/MD5:     6274 abd097b82311d12ab9d0095dac3f920e
          Size/MD5:    11230 85fa172925507f83aade40478755a640

  lpia architecture (Low Power Intel Architecture):

          Size/MD5:   178528 6c38679ccf2f15472b125ab385aea232
          Size/MD5:   235774 5be19819dbae74a5ce75fdb653f3f3f6
          Size/MD5:   127640 747e3ebae6796377b62391bc7738fa14
          Size/MD5:     6122 fd52e98057e643705b2e8a9433256046
          Size/MD5:    11284 bdf6765cb1655577d5140e0fd5367556

  powerpc architecture (Apple Macintosh G3/G4/G5):

          Size/MD5:   221288 6e7ed33c09eedff6fa8591240a0f73cf
          Size/MD5:   256324 126de3077a84e0e0476293fff4a9e166
          Size/MD5:   137082 3f0452f2d9a5651517a77189ff2aec98
          Size/MD5:     8722 6f8b287c5fc7a7cd125a76e331866e1a
          Size/MD5:    14228 8b742dac3af6a1e2bc832c4cbea9829d

  sparc architecture (Sun SPARC/UltraSPARC):

          Size/MD5:   183798 1675983d18499b14fc89910828a5673d
          Size/MD5:   237646 b2b5c339bf9fc368e16af644de35b6aa
          Size/MD5:   123998 b6071b6cffd26da1a5b1eb188322bbc5
          Size/MD5:     5974 c0906d3bcebd191f70a55c4969d4c5ff
          Size/MD5:    12018 88d2b2e7354ff9f52da6d62d6e7ad732


Ubuntu 801-1: tiff vulnerability

July 13, 2009
Tielei Wang and Tom Lane discovered that the TIFF library did not correctly handle certain malformed TIFF images

Summary

Update Instructions

References

Severity
tiff vulnerability

Package Information

Related News