| From: |
| Mageia Updates <buildsystem-daemon@mageia.org> |
| To: |
| updates-announce@ml.mageia.org |
| Subject: |
| [updates-announce] MGASA-2012-0181: libtiff-3.9.5-1.5.mga1
(1/core), libtiff-4.0.1-2.2.mga2 (2/core) |
| Date: |
| Tue, 24 Jul 2012 13:50:35 +0200 |
| Message-ID: |
| <20120724115035.GA27229@valstar.mageia.org> |
| Archive-link: |
| Article, Thread
|
MGASA-2012-0181
Date: July 24th, 2012
Affected releases: 1, 2
Description:
Updated libtiff packages fix security vulnerability:
Huzaifa Sidhpurwala discovered that the tiff2pdf utility incorrectly
handled certain malformed TIFF images. If a user or automated system
were tricked into opening a specially crafted TIFF image, a remote
attacker could crash the application, leading to a denial of service,
or possibly execute arbitrary code with user privileges
(CVE-2012-3401).
Updated Packages:
Mageia 1:
libtiff-progs-3.9.5-1.5.mga1
lib(64)tiff3-3.9.5-1.5.mga1
lib(64)tiff-devel-3.9.5-1.5.mga1
lib(64)tiff-static-devel-3.9.5-1.5.mga1
Mageia 2:
libtiff-progs-4.0.1-2.2.mga2
lib(64)tiff5-4.0.1-2.2.mga2
lib(64)tiff-devel-4.0.1-2.2.mga2
lib(64)tiff-static-devel-4.0.1-2.2.mga2
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3401
http://www.ubuntu.com/usn/usn-1511-1/
https://bugs.mageia.org/show_bug.cgi?id=6833
https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-...
(
Log in to post comments)