LibTIFF TIFFDUMP Heap Corruption Integer Overflow Vulnerability Solution:
SCO has released an advisory (SCOSA-2005.19) and fixes to address this issue for UnixWare platforms. Please see the referenced advisory for further information.
RedHat has released two advisories called FEDORA-2005-597 and FEDORA-2005-598 to address this issue in Fedora Core 2 and 3. Please see the referenced advisories for further information.
Gentoo Linux has released advisory GLSA 200501-06 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=media-libs/tiff-3.7.1-r1"
Please see the referenced advisory for further information.
Debian GNU/Linux has released advisory DSA 626-1 to address this issue. Please see the referenced advisory for further information.
Ubuntu Linux has released advisory USN-54-1 to address this issue. Please see the referenced advisory for further information.
Mandrake has released advisory MDKSA-2005:001 to address various issues in libtiff. Please see the referenced advisory for more information.
Mandrake has released an advisory MDKSA-2005:002 to address various issues in wxGTK2. Please see the referenced advisory for more information.
SUSE has released advisory SUSE-SA:2005:001 to address various issues in libtiff. Please see the referenced advisory for more information.
Red Hat has released an advisory (RHSA-2005:019-11) to address issues in libtiff. Please see the advisory in Web references for more information.
TurboLinux has released a security announcement and fixes to address this and other vulnerabilities. Please see the referenced announcement for further information regarding obtaining and applying appropriate updates.
Conectiva had released advisory CLA-2005:920 to address various issues in libtiff3. Please see the referenced advisory for more information.
SGI has released advisory 20050101-01-U (SGI Advanced Linux Environment 3 Security Update #23) to address various issues in SGI Advanced Linux Environment 3. This advisory includes updated SGI ProPack 3 Service Pack 3 packages and patch 10137. Please see the referenced advisory for more information.
Avaya has released advisory ASA-2005-021 to document the affected versions of Avaya products. Please see the referenced advisory for further information.
Mandrake has released advisory MDKSA-2005:052 to address various issues affecting kdegraphics. Please see the referenced advisory for more information.
SGI ProPack 3.0
LibTIFF LibTIFF 3.5.5
LibTIFF LibTIFF 3.5.7
LibTIFF LibTIFF 3.6.1
SCO Unixware 7.1.4