LWN.net Logo

libtiff: multiple denial of service flaws

Package(s):libtiff CVE #(s):CVE-2010-2481 CVE-2010-2483 CVE-2010-2595 CVE-2010-2597
Created:July 8, 2010 Updated:March 15, 2011
Description:

From the Red Hat advisory:

Multiple input validation flaws were discovered in libtiff. An attacker could use these flaws to create a specially-crafted TIFF file that, when opened, would cause an application linked against libtiff to crash. (CVE-2010-2481, CVE-2010-2483, CVE-2010-2595, CVE-2010-2597)

Alerts:
Ubuntu USN-1085-2 2011-03-15
Ubuntu USN-1085-1 2011-03-07
MeeGo MeeGo-SA-10:27 2010-09-03
MeeGo MeeGo-SA-10:34 2010-10-09
rPath rPSA-2010-0064-1 2010-10-17
Mandriva MDVSA-2010:146 2010-08-06
Mandriva MDVSA-2010:145 2010-08-06
CentOS CESA-2010:0519 2010-07-14
CentOS CESA-2010:0519 2010-07-21
Red Hat RHSA-2010:0519-01 2010-07-08
Gentoo 201209-02 2012-09-23
Debian DSA-2552-1 2012-09-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds