BugTraq
[USN-1120-1] tiff vulnerability Apr 21 2011 01:38PM
Marc Deslauriers (marc deslauriers canonical com)
========================================================================
==
Ubuntu Security Notice USN-1120-1
April 21, 2011

tiff vulnerability
========================================================================
==

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.10
- Ubuntu 10.04 LTS

Summary:

The TIFF library could be made to run programs as your login if it opened a
specially crafted file.

Software Description:
- tiff: TIFF manipulation and conversion tools

Details:

It was discovered that the TIFF library incorrectly handled certain JPEG
data. If a user or automated system were tricked into opening a specially
crafted TIFF image, a remote attacker could execute arbitrary code with
user privileges, or crash the application, leading to a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.10:
libtiff4 3.9.4-2ubuntu0.4

Ubuntu 10.04 LTS:
libtiff4 3.9.2-2ubuntu0.7

After a standard system update you need to restart your session to make
all the necessary changes.

References:
CVE-2009-5022

Package Information:
https://launchpad.net/ubuntu/+source/tiff/3.9.4-2ubuntu0.4
https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.7

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJNsDNeAAoJEGVp2FWnRL6TYSkQAJxtjHDSGpkcfTXDMixlsbhC
QMLEFd01mkr8ld2IuO6TRUjnvz2FYW8AVlX69YHTanb1F9crVgJdaAOFnJXa/mPN
YhB5Jk9BaXgcu2+6PxgPEbELTQuL4C4asowqmXLJAoelGp0HpYmXnTlx+JSFlqcx
105ltrbfLzVd3rJ5/HPaZCdPb8c0eK7WAyIcZDw0KfEecIoLKQmFGuQ8YTEqUexH
4rociu5LmrxUzsnLgodkR0E+93wqzjBy97XAx5/5ANsZwr4JlevZPbzPQaQn+s++
e7h7YaUXEO3g376pMI+Nner0i10VuqDG608ICjQMh7Aq2c2EVVgiacz6Yr0LpDyu
1HiFvYBf2lw5L+i7MV6/RBg53XkZEfHaHx1F6IQ36HgsJpHJPZwFBWwucxALwj/s
7QtNQ4NQ5WrEM9HO2JD0fJajZ6oZjj8G6/txYjIaxC8NIRbgnrZkyRpM6vrFgy93
eti0PWSB7eddg3dvzpSangmd/4J9jRcuS910ia6DMr+0cUkXRpzL/Qft+Dh41Nun
mji0OcFSxOfgYeM7inE3s8Cf9FP0mevIvPq1c/Y4nSLWGr1X9Y0JBEuzxoB5GTaO
G3b8HfgunS9JOqWh/FHQhIGX68aLRAFXnG3CJHp1jdMAmZN3n7mu6jTZl0G2TSBK
hvQRpOBDIfx5Nq+IKVND
=HPa0
-----END PGP SIGNATURE-----

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus