LWN.net Logo

Advertisement

Front, Kernel, Security, Distributions, Development. See your byline here on LWN.net.

Advertise here

libtiff: insufficient validation

Package(s):libtiff CVE #(s):
Created:July 29, 2005 Updated:August 18, 2005
Description: Wouter Hanegraaff discovered that the TIFF library did not sufficiently validate the "YCbCr subsampling" value in TIFF image headers. Decoding a malicious image with a zero value resulted in an arithmetic exception, which caused the program that uses the TIFF library to crash. This leads to a Denial of Service in server applications that use libtiff (like the CUPS printing system) and can cause data loss in, for example, the Evolution email client.
Alerts:
Mandriva MDKSA-2005:143 2005-08-17
Mandriva MDKSA-2005:144 2005-08-18
Mandriva MDKSA-2005:142 2005-08-17
Ubuntu USN-156-1 2005-07-29

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds