USN-6827-1: LibTIFF vulnerability
Published Jun 11, 2024
·Updated
It was discovered that LibTIFF incorrectly handled memory when performing certain cropping operations, leading to a heap buffer overflow. An attacker could use this issue to cause a denial of service, or possibly execute arbitrary code.
Affected Software
28 affected componentsFixes available
All of the following
ubuntu/libtiff-tools<4.5.1+git230720-4ubuntu2.1
4.5.1+git230720-4ubuntu2.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/libtiff6<4.5.1+git230720-4ubuntu2.1
4.5.1+git230720-4ubuntu2.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/libtiff-tools<4.5.1+git230720-1ubuntu1.2
4.5.1+git230720-1ubuntu1.2
Ubuntu Ubuntu=23.10
All of the following
ubuntu/libtiff6<4.5.1+git230720-1ubuntu1.2
4.5.1+git230720-1ubuntu1.2
Ubuntu Ubuntu=23.10
All of the following
ubuntu/libtiff-tools<4.3.0-6ubuntu0.9
4.3.0-6ubuntu0.9
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libtiff5<4.3.0-6ubuntu0.9
4.3.0-6ubuntu0.9
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libtiff-tools<4.1.0+git191117-2ubuntu0.20.04.13
4.1.0+git191117-2ubuntu0.20.04.13
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libtiff5<4.1.0+git191117-2ubuntu0.20.04.13
4.1.0+git191117-2ubuntu0.20.04.13
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libtiff-tools<4.0.9-5ubuntu0.10+esm6
4.0.9-5ubuntu0.10+esm6
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libtiff5<4.0.9-5ubuntu0.10+esm6
4.0.9-5ubuntu0.10+esm6
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libtiff-tools<4.0.6-1ubuntu0.8+esm16
4.0.6-1ubuntu0.8+esm16
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libtiff5<4.0.6-1ubuntu0.8+esm16
4.0.6-1ubuntu0.8+esm16
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libtiff-tools<4.0.3-7ubuntu0.11+esm13
4.0.3-7ubuntu0.11+esm13
Ubuntu Ubuntu=14.04
All of the following
ubuntu/libtiff5<4.0.3-7ubuntu0.11+esm13
4.0.3-7ubuntu0.11+esm13
Ubuntu Ubuntu=14.04
Event History
Jun 11, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6827-1?
The severity of USN-6827-1 is high due to potential denial of service or arbitrary code execution.
2
How do I fix USN-6827-1?
To fix USN-6827-1, update the affected packages to the recommended versions specified in the advisory.
3
What systems are affected by USN-6827-1?
USN-6827-1 affects multiple versions of Ubuntu including 22.04, 23.10, and 24.04.
4
What packages are impacted by USN-6827-1?
The impacted packages in USN-6827-1 include libtiff-tools and libtiff6.
5
What is the cause of the vulnerability in USN-6827-1?
The vulnerability in USN-6827-1 is caused by improper memory handling during cropping operations in LibTIFF.