Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 430
Alerts This Week
Warning Icon 1 430

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
219

Rocky Linux 8 RLSA-2022:1810 Moderate: LibTiff Security Fix

Moderate: libtiff security update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2022:1810', 'synopsis': 'Moderate: libtiff security update', 'severity': 'Moderate', 'topic': 'An update for libtiff is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': 'The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\nAdditional Changes:\nFor detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['2004031'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2020-19131.json:::CVE-2020-19131'], 'references': [], 'publishedAt': '2022-05-18T19:44:12.752066Z', 'rpms': ['libtiff-4.0.9-21.el8.aarch64.rpm', 'libtiff-4.0.9-21.el8.i686.rpm', 'libtiff-4.0.9-21.el8.src.rpm', 'libtiff-4.0.9-21.el8.x86_64.rpm', 'libtiff-debuginfo-4.0.9-21.el8.aarch64.rpm', 'libtiff-debuginfo-4.0.9-21.el8.i686.rpm', 'libtiff-debuginfo-4.0.9-21.el8.x86_64.rpm', 'libtiff-debugsource-4.0.9-21.el8.aarch64.rpm', 'libtiff-debugsource-4.0.9-21.el8.i686.rpm', 'libtiff-debugsource-4.0.9-21.el8.x86_64.rpm', 'libtiff-devel-4.0.9-21.el8.aarch64.rpm', 'libtiff-devel-4.0.9-21.el8.i686.rpm', 'libtiff-devel-4.0.9-21.el8.x86_64.rpm', 'libtiff-tools-4.0.9-21.el8.aarch64.rpm', 'libtiff-tools-4.0.9-21.el8.x86_64.rpm', 'libtiff-tools-debuginfo-4.0.9-21.el8.aarch64.rpm', 'libtiff-tools-debuginfo-4.0.9-21.el8.x86_64.rpm']}\. Rocky Linux 8 issued a security patch for the libtiff library, vital forTIFF image handling. Users should promptly update to ensure system protection and reliability. libtiff Security, Rocky Linux Update, Moderate Security Advisory. . LinuxSecurity.com Team

Calendar%202 Sep 02, 2022 Rocky Linux
98

Red Hat Enterprise Linux 6: RHSA-2014:0222-01 Moderate: Libtiff Issues

Updated libtiff packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having Moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libtiff security update Advisory ID: RHSA-2014:0222-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2014:0222.html Issue date: 2014-02-27 CVE Names: CVE-2010-2596 CVE-2013-1960 CVE-2013-1961 CVE-2013-4231 CVE-2013-4232 CVE-2013-4243 CVE-2013-4244 ==================================================================== 1. Summary: Updated libtiff packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. A heap-based buffer overflow and a use-after-free flaw were found in the tiff2pdf tool. An attacker could use these flaws to create a specially crafted TIFF file that would cause tiff2pdf to crash or, possibly,execute arbitrary code. (CVE-2013-1960, CVE-2013-4232) Multiple buffer overflow flaws were found in the gif2tiff tool. An attacker could use these flaws to create a specially crafted GIF file that could cause gif2tiff to crash or, possibly, execute arbitrary code. (CVE-2013-4231, CVE-2013-4243, CVE-2013-4244) A flaw was found in the way libtiff handled OJPEG-encoded TIFF images. An attacker could use this flaw to create a specially crafted TIFF file that would cause an application using libtiff to crash. (CVE-2010-2596) Multiple buffer overflow flaws were found in the tiff2pdf tool. An attacker could use these flaws to create a specially crafted TIFF file that would cause tiff2pdf to crash. (CVE-2013-1961) Red Hat would like to thank Emmanuel Bouillon of NCI Agency for reporting CVE-2013-1960 and CVE-2013-1961. The CVE-2013-4243 issue was discovered by Murray McAllister of the Red Hat Security Response Team, and the CVE-2013-4244 issue was discovered by Huzaifa Sidhpurwala of the Red Hat Security Response Team. All libtiff users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. All running applications linked against libtiff must be restarted for this update to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 610759 - CVE-2010-2596 libtiff: assertion failure on downsampled OJPEG file 952131 - CVE-2013-1961 libtiff (tiff2pdf): Stack-based buffer overflow with malformed image-length and resolution 952158 - CVE-2013-1960 libtiff (tiff2pdf): Heap-based buffer overflow in t2_process_jpeg_strip() 995965 - CVE-2013-4231 libtiff (gif2tiff): GIF LZW decoder missing datasize value check 995975 - CVE-2013-4232 libtiff (tiff2pdf): use-after-free int2p_readwrite_pdf_image() 996052 - CVE-2013-4243 libtiff (gif2tiff): possible heap-based buffer overflow in readgifimage() 996468 - CVE-2013-4244 libtiff (gif2tiff): OOB Write in LZW decompressor 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: i386: libtiff-3.9.4-10.el6_5.i686.rpm libtiff-debuginfo-3.9.4-10.el6_5.i686.rpm x86_64: libtiff-3.9.4-10.el6_5.i686.rpm libtiff-3.9.4-10.el6_5.x86_64.rpm libtiff-debuginfo-3.9.4-10.el6_5.i686.rpm libtiff-debuginfo-3.9.4-10.el6_5.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: i386: libtiff-debuginfo-3.9.4-10.el6_5.i686.rpm libtiff-devel-3.9.4-10.el6_5.i686.rpm libtiff-static-3.9.4-10.el6_5.i686.rpm x86_64: libtiff-debuginfo-3.9.4-10.el6_5.i686.rpm libtiff-debuginfo-3.9.4-10.el6_5.x86_64.rpm libtiff-devel-3.9.4-10.el6_5.i686.rpm libtiff-devel-3.9.4-10.el6_5.x86_64.rpm libtiff-static-3.9.4-10.el6_5.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: libtiff-3.9.4-10.el6_5.i686.rpm libtiff-3.9.4-10.el6_5.x86_64.rpm libtiff-debuginfo-3.9.4-10.el6_5.i686.rpm libtiff-debuginfo-3.9.4-10.el6_5.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: libtiff-debuginfo-3.9.4-10.el6_5.i686.rpm libtiff-debuginfo-3.9.4-10.el6_5.x86_64.rpm libtiff-devel-3.9.4-10.el6_5.i686.rpm libtiff-devel-3.9.4-10.el6_5.x86_64.rpm libtiff-static-3.9.4-10.el6_5.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: i386: libtiff-3.9.4-10.el6_5.i686.rpm libtiff-debuginfo-3.9.4-10.el6_5.i686.rpm libtiff-devel-3.9.4-10.el6_5.i686.rpm ppc64: libtiff-3.9.4-10.el6_5.ppc.rpm libtiff-3.9.4-10.el6_5.ppc64.rpm libtiff-debuginfo-3.9.4-10.el6_5.ppc.rpm libtiff-debuginfo-3.9.4-10.el6_5.ppc64.rpm libtiff-devel-3.9.4-10.el6_5.ppc.rpm libtiff-devel-3.9.4-10.el6_5.ppc64.rpm s390x: libtiff-3.9.4-10.el6_5.s390.rpm libtiff-3.9.4-10.el6_5.s390x.rpm libtiff-debuginfo-3.9.4-10.el6_5.s390.rpm libtiff-debuginfo-3.9.4-10.el6_5.s390x.rpm libtiff-devel-3.9.4-10.el6_5.s390.rpm libtiff-devel-3.9.4-10.el6_5.s390x.rpm x86_64: libtiff-3.9.4-10.el6_5.i686.rpm libtiff-3.9.4-10.el6_5.x86_64.rpm libtiff-debuginfo-3.9.4-10.el6_5.i686.rpm libtiff-debuginfo-3.9.4-10.el6_5.x86_64.rpm libtiff-devel-3.9.4-10.el6_5.i686.rpm libtiff-devel-3.9.4-10.el6_5.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): Source: i386: libtiff-debuginfo-3.9.4-10.el6_5.i686.rpm libtiff-static-3.9.4-10.el6_5.i686.rpm ppc64: libtiff-debuginfo-3.9.4-10.el6_5.ppc64.rpm libtiff-static-3.9.4-10.el6_5.ppc64.rpm s390x: libtiff-debuginfo-3.9.4-10.el6_5.s390x.rpm libtiff-static-3.9.4-10.el6_5.s390x.rpm x86_64: libtiff-debuginfo-3.9.4-10.el6_5.x86_64.rpm libtiff-static-3.9.4-10.el6_5.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: i386: libtiff-3.9.4-10.el6_5.i686.rpm libtiff-debuginfo-3.9.4-10.el6_5.i686.rpm libtiff-devel-3.9.4-10.el6_5.i686.rpm x86_64: libtiff-3.9.4-10.el6_5.i686.rpm libtiff-3.9.4-10.el6_5.x86_64.rpm libtiff-debuginfo-3.9.4-10.el6_5.i686.rpm libtiff-debuginfo-3.9.4-10.el6_5.x86_64.rpm libtiff-devel-3.9.4-10.el6_5.i686.rpm libtiff-devel-3.9.4-10.el6_5.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: i386: libtiff-debuginfo-3.9.4-10.el6_5.i686.rpm libtiff-static-3.9.4-10.el6_5.i686.rpm x86_64: libtiff-debuginfo-3.9.4-10.el6_5.x86_64.rpm libtiff-static-3.9.4-10.el6_5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2010-2596 https://access.redhat.com/security/cve/CVE-2013-1960 https://access.redhat.com/security/cve/CVE-2013-1961 https://access.redhat.com/security/cve/CVE-2013-4231 https://access.redhat.com/security/cve/CVE-2013-4232 https://access.redhat.com/security/cve/CVE-2013-4243 https://access.redhat.com/security/cve/CVE-2013-4244 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. . The recent update from Red Hat for libpng resolves various security vulnerabilities classified as moderate; users are advised to upgrade.. libtiff Update, Red Hat Security, Moderate Advisory, Threat Mitigation, Buffer Overflow Fix. . LinuxSecurity.com Team

Calendar%202 Feb 27, 2014 Red Hat
98

Red Hat Enterprise Linux: RHSA-2010-0520 critical: libtiff buffer overflow

Updated libtiff packages that fix two security issues are now available for Red Hat Enterprise Linux 3. The Red Hat Security Response Team has rated this update as having important security impact. Common Vulnerability Scoring System (CVSS) base. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: libtiff security update Advisory ID: RHSA-2010:0520-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2010:0520.html Issue date: 2010-07-08 CVE Names: CVE-2010-1411 CVE-2010-2598 ==================================================================== 1. Summary: Updated libtiff packages that fix two security issues are now available for Red Hat Enterprise Linux 3. The Red Hat Security Response Team has rated this update as having important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Description: The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Multiple integer overflow flaws, leading to a buffer overflow, were discovered in libtiff. An attacker could use these flaws to create a specially-crafted TIFF file that, when opened, would cause an application linked against libtiff to crash or, possibly, execute arbitrary code. (CVE-2010-1411) An input validation flaw was discovered in libtiff. An attacker could use this flaw to create a specially-crafted TIFF file that, when opened, would cause an application linked against libtiff tocrash. (CVE-2010-2598) Red Hat would like to thank Apple Product Security for responsibly reporting the CVE-2010-1411 flaw, who credit Kevin Finisterre of digitalmunition.com for the discovery of the issue. All libtiff users are advised to upgrade to these updated packages, which contain backported patches to resolve these issues. All running applications linked against libtiff must be restarted for this update to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 592361 - CVE-2010-1411 libtiff: integer overflows leading to heap overflow in Fax3SetupState 610786 - CVE-2010-2598 libtiff: crash when reading image with not configured compression 6. Package List: Red Hat Enterprise Linux AS version 3: Source: i386: libtiff-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-devel-3.5.7-34.el3.i386.rpm ia64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.ia64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.ia64.rpm libtiff-devel-3.5.7-34.el3.ia64.rpm ppc: libtiff-3.5.7-34.el3.ppc.rpm libtiff-3.5.7-34.el3.ppc64.rpm libtiff-debuginfo-3.5.7-34.el3.ppc.rpm libtiff-debuginfo-3.5.7-34.el3.ppc64.rpm libtiff-devel-3.5.7-34.el3.ppc.rpm s390: libtiff-3.5.7-34.el3.s390.rpm libtiff-debuginfo-3.5.7-34.el3.s390.rpm libtiff-devel-3.5.7-34.el3.s390.rpm s390x: libtiff-3.5.7-34.el3.s390.rpm libtiff-3.5.7-34.el3.s390x.rpm libtiff-debuginfo-3.5.7-34.el3.s390.rpm libtiff-debuginfo-3.5.7-34.el3.s390x.rpm libtiff-devel-3.5.7-34.el3.s390x.rpm x86_64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.x86_64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.x86_64.rpm libtiff-devel-3.5.7-34.el3.x86_64.rpm Red Hat Desktop version3: Source: i386: libtiff-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-devel-3.5.7-34.el3.i386.rpm x86_64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.x86_64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.x86_64.rpm libtiff-devel-3.5.7-34.el3.x86_64.rpm Red Hat Enterprise Linux ES version 3: Source: i386: libtiff-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-devel-3.5.7-34.el3.i386.rpm ia64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.ia64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.ia64.rpm libtiff-devel-3.5.7-34.el3.ia64.rpm x86_64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.x86_64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.x86_64.rpm libtiff-devel-3.5.7-34.el3.x86_64.rpm Red Hat Enterprise Linux WS version 3: Source: i386: libtiff-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-devel-3.5.7-34.el3.i386.rpm ia64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.ia64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.ia64.rpm libtiff-devel-3.5.7-34.el3.ia64.rpm x86_64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.x86_64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.x86_64.rpm libtiff-devel-3.5.7-34.el3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2010-1411 https://access.redhat.com/security/cve/CVE-2010-2598 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2010 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4(GNU/Linux) iD8DBQFMNfOPXlSAg2UNWIIRAurJAJkB8wmjd26wEaNzyP/VrsZm5JRu4ACdGLLi Mq1vv6XR9uZXwmk9oGLmaUU=wfMT -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial libjpeg vulnerability patch resolves two major flaws in Ubuntu Server, bolstering your network's protection.. Red Hat Enterprise Linux, libtiff update, security patch, critical update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 08, 2010 Important Red Hat
98

Red Hat EL 3 RHSA-2010:0520-01 Critical: libtiff Buffer Overflow

Updated libtiff packages that fix two security issues are now available for Red Hat Enterprise Linux 3. The Red Hat Security Response Team has rated this update as having [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: libtiff security update Advisory ID: RHSA-2010:0520-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2010:0520.html Issue date: 2010-07-08 CVE Names: CVE-2010-1411 CVE-2010-2598 ==================================================================== 1. Summary: Updated libtiff packages that fix two security issues are now available for Red Hat Enterprise Linux 3. The Red Hat Security Response Team has rated this update as having important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Description: The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Multiple integer overflow flaws, leading to a buffer overflow, were discovered in libtiff. An attacker could use these flaws to create a specially-crafted TIFF file that, when opened, would cause an application linked against libtiff to crash or, possibly, execute arbitrary code. (CVE-2010-1411) An input validation flaw was discovered in libtiff. An attacker could use this flaw to create a specially-crafted TIFF file that, when opened, would cause an application linked against libtiff to crash. (CVE-2010-2598) Red Hat would like to thank Apple Product Security for responsibly reporting theCVE-2010-1411 flaw, who credit Kevin Finisterre of digitalmunition.com for the discovery of the issue. All libtiff users are advised to upgrade to these updated packages, which contain backported patches to resolve these issues. All running applications linked against libtiff must be restarted for this update to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 592361 - CVE-2010-1411 libtiff: integer overflows leading to heap overflow in Fax3SetupState 610786 - CVE-2010-2598 libtiff: crash when reading image with not configured compression 6. Package List: Red Hat Enterprise Linux AS version 3: Source: i386: libtiff-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-devel-3.5.7-34.el3.i386.rpm ia64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.ia64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.ia64.rpm libtiff-devel-3.5.7-34.el3.ia64.rpm ppc: libtiff-3.5.7-34.el3.ppc.rpm libtiff-3.5.7-34.el3.ppc64.rpm libtiff-debuginfo-3.5.7-34.el3.ppc.rpm libtiff-debuginfo-3.5.7-34.el3.ppc64.rpm libtiff-devel-3.5.7-34.el3.ppc.rpm s390: libtiff-3.5.7-34.el3.s390.rpm libtiff-debuginfo-3.5.7-34.el3.s390.rpm libtiff-devel-3.5.7-34.el3.s390.rpm s390x: libtiff-3.5.7-34.el3.s390.rpm libtiff-3.5.7-34.el3.s390x.rpm libtiff-debuginfo-3.5.7-34.el3.s390.rpm libtiff-debuginfo-3.5.7-34.el3.s390x.rpm libtiff-devel-3.5.7-34.el3.s390x.rpm x86_64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.x86_64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.x86_64.rpm libtiff-devel-3.5.7-34.el3.x86_64.rpm Red Hat Desktop version3: Source: i386: libtiff-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-devel-3.5.7-34.el3.i386.rpm x86_64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.x86_64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.x86_64.rpm libtiff-devel-3.5.7-34.el3.x86_64.rpm Red Hat Enterprise Linux ES version 3: Source: i386: libtiff-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-devel-3.5.7-34.el3.i386.rpm ia64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.ia64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.ia64.rpm libtiff-devel-3.5.7-34.el3.ia64.rpm x86_64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.x86_64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.x86_64.rpm libtiff-devel-3.5.7-34.el3.x86_64.rpm Red Hat Enterprise Linux WS version 3: Source: i386: libtiff-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-devel-3.5.7-34.el3.i386.rpm ia64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.ia64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.ia64.rpm libtiff-devel-3.5.7-34.el3.ia64.rpm x86_64: libtiff-3.5.7-34.el3.i386.rpm libtiff-3.5.7-34.el3.x86_64.rpm libtiff-debuginfo-3.5.7-34.el3.i386.rpm libtiff-debuginfo-3.5.7-34.el3.x86_64.rpm libtiff-devel-3.5.7-34.el3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2010-1411 https://access.redhat.com/security/cve/CVE-2010-2598 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2010 Red Hat, Inc. . ==================================================================== Red Hat Security Advisory Synop. updated, libtiff, packages,security, enterprise, linux. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 08, 2010 Important Red Hat
98

Red Hat: RHSA-2004:577-01 Critical: Libtiff Overflow and Crash Risk

Updated libtiff packages that fix various buffer and integer overflows are now available.. --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated libtiff packages Advisory ID: RHSA-2004:577-01 Issue date: 2004-10-22 Updated on: 2004-10-22 Product: Red Hat Enterprise Linux CVE Names: CAN-2004-0803 CAN-2004-0886 CAN-2004-0804 --------------------------------------------------------------------- 1. Summary: Updated libtiff packages that fix various buffer and integer overflows are now available. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: The libtiff package contains a library of functions for manipulating TIFF (Tagged Image File Format) image format files. TIFF is a widely used file format for bitmapped images. During a source code audit, Chris Evans discovered a number of integer overflow bugs that affect libtiff. An attacker who has the ability to trick a user into opening a malicious TIFF file could cause the application linked to libtiff to crash or possibly execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0886 and CAN-2004-0804 to these issues. Additionally, a number of buffer overflow bugs that affect libtiff have been found. An attacker who has the ability to trick a user into opening a malicious TIFF file could cause the application linked to libtiff to crash or possibly execute arbitrary code. The Common Vulnerabilities and Exposures project(cve.mitre.org) has assigned the name CAN-2004-0803 to this issue. All users are advised to upgrade to these errata packages, which contain fixes for these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/ for more info): 134847 - CAN-2004-0803 buffer overflows in libtiff 134850 - CAN-2004-0886 multiple integer overflows in libtiff 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 81fdc07747655ddf15df50f3e091bd88 libtiff-3.5.5-17.src.rpm i386: 3c3cfb6ea1d426f7dfaf3eba049b01fa libtiff-3.5.5-17.i386.rpm bed65897ba0f56dd646cfe108d16ec53 libtiff-devel-3.5.5-17.i386.rpm ia64: 2dd106332e7f94e7c1b68a259b697527 libtiff-3.5.5-17.ia64.rpm f55c05ad31942a5c55e05afc3f1cffac libtiff-devel-3.5.5-17.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 81fdc07747655ddf15df50f3e091bd88 libtiff-3.5.5-17.src.rpm ia64: 2dd106332e7f94e7c1b68a259b697527 libtiff-3.5.5-17.ia64.rpm f55c05ad31942a5c55e05afc3f1cffac libtiff-devel-3.5.5-17.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 81fdc07747655ddf15df50f3e091bd88 libtiff-3.5.5-17.src.rpm i386: 3c3cfb6ea1d426f7dfaf3eba049b01fa libtiff-3.5.5-17.i386.rpm bed65897ba0f56dd646cfe108d16ec53 libtiff-devel-3.5.5-17.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 81fdc07747655ddf15df50f3e091bd88 libtiff-3.5.5-17.src.rpm i386: 3c3cfb6ea1d426f7dfaf3eba049b01fa libtiff-3.5.5-17.i386.rpm bed65897ba0f56dd646cfe108d16ec53 libtiff-devel-3.5.5-17.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: 63d28c10b3bd0c697395b236c675fc79 libtiff-3.5.7-20.1.src.rpm i386: 818848dcbf461a6f37790579d8c80f0f libtiff-3.5.7-20.1.i386.rpm 41d907de858669e84d1a2c9bad3c5051 libtiff-devel-3.5.7-20.1.i386.rpm ia64: 223bd77614b274ea88e82cc2b7179fc5 libtiff-3.5.7-20.1.ia64.rpm 818848dcbf461a6f37790579d8c80f0f libtiff-3.5.7-20.1.i386.rpm f28363290fa144bdc459ff3804cdf5aa libtiff-devel-3.5.7-20.1.ia64.rpm ppc: 10659dd13f97307f8066a4807f941264 libtiff-3.5.7-20.1.ppc.rpm b439935cb94f59e804e51ec43bf1f990 libtiff-3.5.7-20.1.ppc64.rpm baf93839e20c42f0a60690a19eabd883 libtiff-devel-3.5.7-20.1.ppc.rpm s390: 1455a42e3976cae523bf87e3708ff35e libtiff-3.5.7-20.1.s390.rpm 8a4ba4c7c08f3c7774b1596ff10ba15a libtiff-devel-3.5.7-20.1.s390.rpm s390x: a3be3779774c347e96d761cbd97ff898 libtiff-3.5.7-20.1.s390x.rpm 1455a42e3976cae523bf87e3708ff35e libtiff-3.5.7-20.1.s390.rpm bc686fba5bea3978cdfaa99134615e77 libtiff-devel-3.5.7-20.1.s390x.rpm x86_64: 47246fe4da56c5bd5c75c35a50d7ad7c libtiff-3.5.7-20.1.x86_64.rpm 818848dcbf461a6f37790579d8c80f0f libtiff-3.5.7-20.1.i386.rpm 51458cc4571eff6f68fa528b19acbd68 libtiff-devel-3.5.7-20.1.x86_64.rpm Red Hat Desktop version 3: SRPMS: 63d28c10b3bd0c697395b236c675fc79 libtiff-3.5.7-20.1.src.rpm i386: 818848dcbf461a6f37790579d8c80f0f libtiff-3.5.7-20.1.i386.rpm 41d907de858669e84d1a2c9bad3c5051 libtiff-devel-3.5.7-20.1.i386.rpm x86_64: 47246fe4da56c5bd5c75c35a50d7ad7c libtiff-3.5.7-20.1.x86_64.rpm 818848dcbf461a6f37790579d8c80f0f libtiff-3.5.7-20.1.i386.rpm 51458cc4571eff6f68fa528b19acbd68 libtiff-devel-3.5.7-20.1.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: 63d28c10b3bd0c697395b236c675fc79 libtiff-3.5.7-20.1.src.rpm i386: 818848dcbf461a6f37790579d8c80f0f libtiff-3.5.7-20.1.i386.rpm 41d907de858669e84d1a2c9bad3c5051 libtiff-devel-3.5.7-20.1.i386.rpm ia64: 223bd77614b274ea88e82cc2b7179fc5 libtiff-3.5.7-20.1.ia64.rpm 818848dcbf461a6f37790579d8c80f0f libtiff-3.5.7-20.1.i386.rpm f28363290fa144bdc459ff3804cdf5aa libtiff-devel-3.5.7-20.1.ia64.rpm x86_64: 47246fe4da56c5bd5c75c35a50d7ad7c libtiff-3.5.7-20.1.x86_64.rpm 818848dcbf461a6f37790579d8c80f0f libtiff-3.5.7-20.1.i386.rpm 51458cc4571eff6f68fa528b19acbd68 libtiff-devel-3.5.7-20.1.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: 63d28c10b3bd0c697395b236c675fc79 libtiff-3.5.7-20.1.src.rpm i386: 818848dcbf461a6f37790579d8c80f0f libtiff-3.5.7-20.1.i386.rpm 41d907de858669e84d1a2c9bad3c5051 libtiff-devel-3.5.7-20.1.i386.rpm ia64: 223bd77614b274ea88e82cc2b7179fc5 libtiff-3.5.7-20.1.ia64.rpm 818848dcbf461a6f37790579d8c80f0f libtiff-3.5.7-20.1.i386.rpm f28363290fa144bdc459ff3804cdf5aa libtiff-devel-3.5.7-20.1.ia64.rpm x86_64: 47246fe4da56c5bd5c75c35a50d7ad7c libtiff-3.5.7-20.1.x86_64.rpm 818848dcbf461a6f37790579d8c80f0f libtiff-3.5.7-20.1.i386.rpm 51458cc4571eff6f68fa528b19acbd68 libtiff-devel-3.5.7-20.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from 7. References: CVE -CVE-2004-0803 CVE -CVE-2004-0886 CVE -CVE-2004-0804 8. Contact: The Red Hat security contact is . More contact details at Copyright 2004 Red Hat, Inc. . Recent libtiff updates released to address critical buffer and integer overflow vulnerabilities in Red Hat platforms. Immediate upgrade suggested.. libtiff update, buffer overflow, integer overflow, security patch, Red Hat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 22, 2004 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200