Moderate: libtiff security update. Date: Thu, 27 Feb 2014 20:17:25 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: libtiff on SL5.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: libtiff security update Advisory ID: SLSA-2014:0223-1 Issue Date: 2014-02-27 CVE Numbers: CVE-2013-1961 CVE-2013-1960 CVE-2013-4231 CVE-2013-4232 CVE-2013-4243 CVE-2013-4244 -- A heap-based buffer overflow and a use-after-free flaw were found in the tiff2pdf tool. An attacker could use these flaws to create a specially crafted TIFF file that would cause tiff2pdf to crash or, possibly, execute arbitrary code. (CVE-2013-1960, CVE-2013-4232) Multiple buffer overflow flaws were found in the gif2tiff tool. An attacker could use these flaws to create a specially crafted GIF file that could cause gif2tiff to crash or, possibly, execute arbitrary code. (CVE-2013-4231, CVE-2013-4243, CVE-2013-4244) Multiple buffer overflow flaws were found in the tiff2pdf tool. An attacker could use these flaws to create a specially crafted TIFF file that would cause tiff2pdf to crash. (CVE-2013-1961) All running applications linked against libtiff must be restarted for this update to take effect. -- SL5 x86_64 libtiff-3.8.2-19.el5_10.i386.rpm libtiff-3.8.2-19.el5_10.x86_64.rpm libtiff-debuginfo-3.8.2-19.el5_10.i386.rpm libtiff-debuginfo-3.8.2-19.el5_10.x86_64.rpm libtiff-devel-3.8.2-19.el5_10.i386.rpm libtiff-devel-3.8.2-19.el5_10.x86_64.rpm i386 libtiff-3.8.2-19.el5_10.i386.rpm libtiff-debuginfo-3.8.2-19.el5_10.i386.rpm libtiff-devel-3.8.2-19.el5_10.i386.rpm - Scientific Linux Development Team . Critical patch release for libjpeg in Scientific Linux addresses memory leak issues. Ensure updates are implemented properly.. libtiff security, Scientific Linux update, buffer overflow fixes. . Severity: Important. LinuxSecurity.com Team
tiff2pdf could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-1511-1 July 19, 2012 tiff vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.04 LTS - Ubuntu 8.04 LTS Summary: tiff2pdf could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - tiff: Tag Image File Format (TIFF) library Details: Huzaifa Sidhpurwala discovered that the tiff2pdf utility incorrectly handled certain malformed TIFF images. If a user or automated system were tricked into opening a specially crafted TIFF image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: libtiff-tools 3.9.5-2ubuntu1.2 Ubuntu 11.10: libtiff-tools 3.9.5-1ubuntu1.3 Ubuntu 11.04: libtiff-tools 3.9.4-5ubuntu6.3 Ubuntu 10.04 LTS: libtiff-tools 3.9.2-2ubuntu0.10 Ubuntu 8.04 LTS: libtiff-tools 3.8.2-7ubuntu3.13 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1511-1 CVE-2012-3401 Package Information: https://launchpad.net/ubuntu/+source/tiff/3.9.5-2ubuntu1.2 https://launchpad.net/ubuntu/+source/tiff/3.9.5-1ubuntu1.3 https://launchpad.net/ubuntu/+source/tiff/3.9.4-5ubuntu6.3 https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.10 https://launchpad.net/ubuntu/+source/tiff/3.8.2-7ubuntu3.13 . This advisory highlights criticalvulnerabilities in the tiff2pdf tool, urging users to apply patches promptly to protect against crashes and code execution risks. Tiff Exploit, Ubuntu 12.04 Advisory, Critical Security Risk. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.