LWN.net Logo

libtiff: arbitrary code execution

Package(s):libtiff CVE #(s):CVE-2009-5022
Created:April 18, 2011 Updated:June 10, 2011
Description: From the Red Hat advisory:

A heap-based buffer overflow flaw was found in the way libtiff processed certain TIFF image files that were compressed with the JPEG compression algorithm. An attacker could use this flaw to create a specially-crafted TIFF file that, when opened, would cause an application linked against libtiff to crash or, possibly, execute arbitrary code.

Alerts:
Debian DSA-2256-1 2011-06-09
Fedora FEDORA-2011-5304 2011-04-13
Red Hat RHSA-2011:0452-01 2011-04-18
Mandriva MDVSA-2011:078 2011-04-23
SUSE SUSE-SR:2011:008 2011-05-03
openSUSE openSUSE-SU-2011:0405-1 2011-04-29
Ubuntu USN-1120-1 2011-04-21
Gentoo 201209-02 2012-09-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds