[USN-1120-1] tiff vulnerability

看板Bugtraq作者時間15年前 (2011/04/22 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
--=-Ugf7Eo/Qrg4fHJyrHpPe Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Ubuntu Security Notice USN-1120-1 April 21, 2011 tiff vulnerability =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: The TIFF library could be made to run programs as your login if it opened a specially crafted file. Software Description: - tiff: TIFF manipulation and conversion tools Details: It was discovered that the TIFF library incorrectly handled certain JPEG data. If a user or automated system were tricked into opening a specially crafted TIFF image, a remote attacker could execute arbitrary code with user privileges, or crash the application, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.10: libtiff4 3.9.4-2ubuntu0.4 Ubuntu 10.04 LTS: libtiff4 3.9.2-2ubuntu0.7 After a standard system update you need to restart your session to make all the necessary changes. References: CVE-2009-5022 Package Information: https://launchpad.net/ubuntu/+source/tiff/3.9.4-2ubuntu0.4 https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.7 --=-Ugf7Eo/Qrg4fHJyrHpPe Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iQIcBAABCgAGBQJNsDNeAAoJEGVp2FWnRL6TYSkQAJxtjHDSGpkcfTXDMixlsbhC QMLEFd01mkr8ld2IuO6TRUjnvz2FYW8AVlX69YHTanb1F9crVgJdaAOFnJXa/mPN YhB5Jk9BaXgcu2+6PxgPEbELTQuL4C4asowqmXLJAoelGp0HpYmXnTlx+JSFlqcx 105ltrbfLzVd3rJ5/HPaZCdPb8c0eK7WAyIcZDw0KfEecIoLKQmFGuQ8YTEqUexH 4rociu5LmrxUzsnLgodkR0E+93wqzjBy97XAx5/5ANsZwr4JlevZPbzPQaQn+s++ e7h7YaUXEO3g376pMI+Nner0i10VuqDG608ICjQMh7Aq2c2EVVgiacz6Yr0LpDyu 1HiFvYBf2lw5L+i7MV6/RBg53XkZEfHaHx1F6IQ36HgsJpHJPZwFBWwucxALwj/s 7QtNQ4NQ5WrEM9HO2JD0fJajZ6oZjj8G6/txYjIaxC8NIRbgnrZkyRpM6vrFgy93 eti0PWSB7eddg3dvzpSangmd/4J9jRcuS910ia6DMr+0cUkXRpzL/Qft+Dh41Nun mji0OcFSxOfgYeM7inE3s8Cf9FP0mevIvPq1c/Y4nSLWGr1X9Y0JBEuzxoB5GTaO G3b8HfgunS9JOqWh/FHQhIGX68aLRAFXnG3CJHp1jdMAmZN3n7mu6jTZl0G2TSBK hvQRpOBDIfx5Nq+IKVND =HPa0 -----END PGP SIGNATURE----- --=-Ugf7Eo/Qrg4fHJyrHpPe--
文章代碼(AID): #1Di73ZFA (Bugtraq)