First published: Thu Jul 08 2010(Updated: )
The libtiff packages contain a library of functions for manipulating Tagged<br>Image File Format (TIFF) files.<br>Multiple integer overflow flaws, leading to a buffer overflow, were<br>discovered in libtiff. An attacker could use these flaws to create a<br>specially-crafted TIFF file that, when opened, would cause an application<br>linked against libtiff to crash or, possibly, execute arbitrary code.<br>(CVE-2010-1411)<br>Multiple input validation flaws were discovered in libtiff. An attacker<br>could use these flaws to create a specially-crafted TIFF file that, when<br>opened, would cause an application linked against libtiff to crash.<br>(CVE-2010-2481, CVE-2010-2483, CVE-2010-2595, CVE-2010-2597)<br>Red Hat would like to thank Apple Product Security for responsibly<br>reporting the CVE-2010-1411 flaw, who credit Kevin Finisterre of<br>digitalmunition.com for the discovery of the issue.<br>All libtiff users are advised to upgrade to these updated packages, which<br>contain backported patches to resolve these issues. All running<br>applications linked against libtiff must be restarted for this update to<br>take effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libtiff | <3.8.2-7.el5_5.5 | 3.8.2-7.el5_5.5 |
redhat/libtiff | <3.8.2-7.el5_5.5 | 3.8.2-7.el5_5.5 |
redhat/libtiff-devel | <3.8.2-7.el5_5.5 | 3.8.2-7.el5_5.5 |
redhat/libtiff-devel | <3.8.2-7.el5_5.5 | 3.8.2-7.el5_5.5 |
redhat/libtiff | <3.6.1-12.el4_8.5 | 3.6.1-12.el4_8.5 |
redhat/libtiff | <3.6.1-12.el4_8.5 | 3.6.1-12.el4_8.5 |
redhat/libtiff-devel | <3.6.1-12.el4_8.5 | 3.6.1-12.el4_8.5 |
redhat/libtiff-devel | <3.6.1-12.el4_8.5 | 3.6.1-12.el4_8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2010:0519 is classified as a moderate severity vulnerability affecting the libtiff packages.
To fix RHSA-2010:0519, update to the appropriate version of libtiff or libtiff-devel, specifically version 3.8.2-7.el5_5.5 or 3.6.1-12.el4_8.5.
RHSA-2010:0519 contains multiple integer overflow flaws in libtiff that can lead to buffer overflow vulnerabilities.
Yes, an attacker can potentially exploit the vulnerabilities in RHSA-2010:0519 to execute arbitrary code via a specially-crafted TIFF file.
RHSA-2010:0519 affects libtiff versions prior to 3.8.2-7.el5_5.5 for EL5 and 3.6.1-12.el4_8.5 for EL4.