LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-5743-1 November 24, 2022 tiff vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - tiff: Tag Image File Format (TIFF) library Details: It was discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libtiff-tools 4.0.6-1ubuntu0.8+esm8 libtiff5 4.0.6-1ubuntu0.8+esm8 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5743-1 CVE-2022-3970 . The LibTIFF library may permit remote code execution or lead to application instability through specifically designed image files when used on Ubuntu 16.04 ESM.. LibTIFF, Denial of Service, Image Processing, Security Notice, Ubuntu 16.04. . LinuxSecurity.com Team
LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-3212-1 February 27, 2017 tiff vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - tiff: Tag Image File Format (TIFF) library Details: It was discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.10: libtiff-tools 4.0.6-2ubuntu0.1 libtiff5 4.0.6-2ubuntu0.1 Ubuntu 16.04 LTS: libtiff-tools 4.0.6-1ubuntu0.1 libtiff5 4.0.6-1ubuntu0.1 Ubuntu 14.04 LTS: libtiff-tools 4.0.3-7ubuntu0.6 libtiff5 4.0.3-7ubuntu0.6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3212-1 CVE-2015-7554, CVE-2015-8668, CVE-2016-10092, CVE-2016-10093, CVE-2016-10094, CVE-2016-3622, CVE-2016-3623, CVE-2016-3624, CVE-2016-3632, CVE-2016-3658, CVE-2016-3945, CVE-2016-3990, CVE-2016-3991, CVE-2016-5314, CVE-2016-5315, CVE-2016-5316, CVE-2016-5317, CVE-2016-5320, CVE-2016-5321, CVE-2016-5322, CVE-2016-5323, CVE-2016-5652, CVE-2016-5875, CVE-2016-6223, CVE-2016-8331, CVE-2016-9273, CVE-2016-9297, CVE-2016-9448, CVE-2016-9453, CVE-2016-9532, CVE-2016-9533, CVE-2016-9534, CVE-2016-9535, CVE-2016-9536, CVE-2016-9537, CVE-2016-9538, CVE-2016-9539, CVE-2016-9540, CVE-2017-5225 Package Information: https://launchpad.net/ubuntu/+source/tiff/4.0.6-2ubuntu0.1 https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1 https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6 . Caution alert USN-7420-3 underscores vulnerabilities in LibPNG, necessitating patching due to critical image processing flaws.. LibTIFF Update, Ubuntu Security, Denial of Service Risk. . Severity: Critical. LinuxSecurity.com Team
LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-2939-1 March 23, 2016 tiff vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - tiff: Tag Image File Format (TIFF) library Details: It was discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: libtiff5 4.0.3-12.3ubuntu2.1 Ubuntu 14.04 LTS: libtiff5 4.0.3-7ubuntu0.4 Ubuntu 12.04 LTS: libtiff4 3.9.5-2ubuntu1.9 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2939-1 CVE-2015-8665, CVE-2015-8683, CVE-2015-8781, CVE-2015-8782, CVE-2015-8783, CVE-2015-8784 Package Information: https://launchpad.net/ubuntu/+source/tiff/4.0.3-12.3ubuntu2.1 https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.4 https://launchpad.net/ubuntu/+source/tiff/3.9.5-2ubuntu1.9 . Recent LibTIFF security flaws in Ubuntu may lead to system crashes or potential remote code execution via specially crafted files. It's advised to apply updates.. LibTIFF Denial of Service, Ubuntu Security Notice, TIFF Library Update. . Severity: Important. LinuxSecurity.com Team
LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-2553-1 March 31, 2015 tiff vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - tiff: Tag Image File Format (TIFF) library Details: William Robinet discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges. (CVE-2014-8127, CVE-2014-8128, CVE-2014-8129, CVE-2014-8130) Paris Zoumpouloglou discovered that LibTIFF incorrectly handled certain malformed BMP images. If a user or automated system were tricked into opening a specially crafted BMP image, a remote attacker could crash the application, leading to a denial of service. (CVE-2014-9330) Michal Zalewski discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges. (CVE-2014-9655) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: libtiff5 4.0.3-10ubuntu0.1 Ubuntu 14.04 LTS: libtiff5 4.0.3-7ubuntu0.2 Ubuntu 12.04 LTS: libtiff4 3.9.5-2ubuntu1.7 Ubuntu 10.04 LTS: libtiff4 3.9.2-2ubuntu0.15 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2553-1 CVE-2014-8127, CVE-2014-8128, CVE-2014-8129, CVE-2014-8130, CVE-2014-9330, CVE-2014-9655 Package Information: https://launchpad.net/ubuntu/+source/tiff/4.0.3-10ubuntu0.1 https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.2 https://launchpad.net/ubuntu/+source/tiff/3.9.5-2ubuntu1.7 https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.15 . Stay informed about LibTIFF vulnerabilities on Ubuntu systems. Apply security patches, upgrade packages, and monitor advisories to safeguard your data.. LibTIFF Vulnerabilities, Ubuntu Security Notice, Denial of Service, Image Handling. . Severity: Critical. LinuxSecurity.com Team
The tiff library for handling TIFF image files contained a stack-based buffer overflow, potentially allowing attackers who can submit such files to a vulnerable system to execute arbitrary code. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2589-1
The TIFF library could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-1498-1 July 05, 2012 tiff vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.04 LTS - Ubuntu 8.04 LTS Summary: The TIFF library could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - tiff: Tag Image File Format (TIFF) library Details: It was discovered that the TIFF library incorrectly handled certain malformed TIFF images. If a user or automated system were tricked into opening a specially crafted TIFF image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges. (CVE-2012-2088) It was discovered that the tiff2pdf utility incorrectly handled certain malformed TIFF images. If a user or automated system were tricked into opening a specially crafted TIFF image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges. (CVE-2012-2113) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: libtiff-tools 3.9.5-2ubuntu1.1 libtiff4 3.9.5-2ubuntu1.1 Ubuntu 11.10: libtiff-tools 3.9.5-1ubuntu1.2 libtiff4 3.9.5-1ubuntu1.2 Ubuntu 11.04: libtiff-tools 3.9.4-5ubuntu6.2 libtiff4 3.9.4-5ubuntu6.2 Ubuntu 10.04 LTS: libtiff-tools 3.9.2-2ubuntu0.9 libtiff4 3.9.2-2ubuntu0.9 Ubuntu 8.04 LTS: libtiff-tools 3.8.2-7ubuntu3.12 libtiff4 3.8.2-7ubuntu3.12 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1498-1 CVE-2012-2088, CVE-2012-2113 Package Information: https://launchpad.net/ubuntu/+source/tiff/3.9.5-2ubuntu1.1 https://launchpad.net/ubuntu/+source/tiff/3.9.5-1ubuntu1.2 https://launchpad.net/ubuntu/+source/tiff/3.9.4-5ubuntu6.2 https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.9 https://launchpad.net/ubuntu/+source/tiff/3.8.2-7ubuntu3.12 . Serious TIFF flaws may lead to application failures or permit unauthorized code runs on Ubuntu platforms. Immediate updates advised.. TIFF Security Issues, Remote Code Execution, Denial of Service. . Severity: Important. LinuxSecurity.com Team
Tavis Ormandy discovered that the Tag Image File Format (TIFF) library is vulnerable to a buffer overflow triggered by a crafted OJPEG file which allows for a crash and potentially execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2256-1
Several problems have been discovered in the TIFF library. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2006-2193, CVE-2006-2656. . - --------------------------------------------------------------------------Debian Security Advisory DSA 1091-1
Get the latest Linux and open source security news straight to your inbox.