First published: Thu Feb 25 2021(Updated: )
It was discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libtiff-tools | <4.1.0+git191117-2ubuntu0.20.10.1 | 4.1.0+git191117-2ubuntu0.20.10.1 |
=20.10 | ||
All of | ||
ubuntu/libtiff5 | <4.1.0+git191117-2ubuntu0.20.10.1 | 4.1.0+git191117-2ubuntu0.20.10.1 |
=20.10 | ||
All of | ||
ubuntu/libtiff-tools | <4.1.0+git191117-2ubuntu0.20.04.1 | 4.1.0+git191117-2ubuntu0.20.04.1 |
=20.04 | ||
All of | ||
ubuntu/libtiff5 | <4.1.0+git191117-2ubuntu0.20.04.1 | 4.1.0+git191117-2ubuntu0.20.04.1 |
=20.04 | ||
All of | ||
ubuntu/libtiff-tools | <4.0.9-5ubuntu0.4 | 4.0.9-5ubuntu0.4 |
=18.04 | ||
All of | ||
ubuntu/libtiff5 | <4.0.9-5ubuntu0.4 | 4.0.9-5ubuntu0.4 |
=18.04 | ||
All of | ||
ubuntu/libtiff-tools | <4.0.6-1ubuntu0.8 | 4.0.6-1ubuntu0.8 |
=16.04 | ||
All of | ||
ubuntu/libtiff5 | <4.0.6-1ubuntu0.8 | 4.0.6-1ubuntu0.8 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-4755-1
libtiff-tools and libtiff5 in Ubuntu versions 20.10, 20.04, 18.04, and 16.04
The vulnerability could allow a remote attacker to crash the application or execute arbitrary code with user privileges.
Update to libtiff-tools version 4.1.0+git191117-2ubuntu0.20.10.1 for Ubuntu 20.10, libtiff-tools version 4.1.0+git191117-2ubuntu0.20.04.1 for Ubuntu 20.04, libtiff-tools version 4.0.9-5ubuntu0.4 for Ubuntu 18.04, and libtiff-tools version 4.0.6-1ubuntu0.8 for Ubuntu 16.04.
You can find more information about the USN-4755-1 vulnerability on the Ubuntu Security Notices website: [link].