-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -------------------------------------------------------------------------- PACKAGE : libtiff3 SUMMARY : Fixes for libtiff vulnerabilities DATE : 2004-11-08 11:19:00 ID : CLA-2004:888 RELEVANT RELEASES : 9, 10 - ------------------------------------------------------------------------- DESCRIPTION libtiff[1] is a library for handling TIFF images. This announcement fixes several integer overflow vulnerabilities that were encountered in libtiff. The fixed vulnerabilities are: CAN-2004-0803: Chris Evans encountered several problems in the RLE (Run Length Encoding) decoders that could lead to an arbitrary code execution vulnerability through a specially crafted image. CAN-2004-0804: Matthias Clasen encountered a division by zero through an integer overflow that could lead to a denial of service vulnerability which could be triggered by a specially crafted image. CAN-2004-0886: Dmitry V. Levin encountered several integer overflows that caused malloc issues which could result in either plain a crash or memory corruption. SOLUTION It is recommended that all libtiff users upgrade their packages. IMPORTANT: all applications linked against libff must be restarted after the upgrade in order to close the vulnerabilities. REFERENCES 1.http://www.libtiff.org 2.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0803 3.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0804 4.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0886 UPDATED PACKAGES ftp://atualizacoes.conectiva.com.br/10/SRPMS/libtiff3-3.5.7-53035U10_1cl.src.rpm ftp://atualizacoes.conectiva.com.br/10/RPMS/libtiff-devel-3.5.7-53035U10_1cl.i386.rpm ftp://atualizacoes.conectiva.com.br/10/RPMS/libtiff-devel-static-3.5.7-53035U10_1cl.i386.rpm ftp://atualizacoes.conectiva.com.br/10/RPMS/libtiff-progs-3.5.7-53035U10_1cl.i386.rpm ftp://atualizacoes.conectiva.com.br/10/RPMS/libtiff3-3.5.7-53035U10_1cl.i386.rpm ftp://atualizacoes.conectiva.com.br/9/SRPMS/libtiff3-3.5.7-8492U90_1cl.src.rpm ftp://atualizacoes.conectiva.com.br/9/RPMS/libtiff-devel-3.5.7-8492U90_1cl.i386.rpm ftp://atualizacoes.conectiva.com.br/9/RPMS/libtiff-devel-static-3.5.7-8492U90_1cl.i386.rpm ftp://atualizacoes.conectiva.com.br/9/RPMS/libtiff-progs-3.5.7-8492U90_1cl.i386.rpm ftp://atualizacoes.conectiva.com.br/9/RPMS/libtiff3-3.5.7-8492U90_1cl.i386.rpm ADDITIONAL INSTRUCTIONS The apt tool can be used to perform RPM packages upgrades: - run: apt-get update - after that, execute: apt-get upgrade Detailed instructions regarding the use of apt and upgrade examples can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en - ------------------------------------------------------------------------- All packages are signed with Conectiva's GPG key. The key and instructions on how to import it can be found at http://distro.conectiva.com.br/seguranca/chave/?idioma=en Instructions on how to check the signatures of the RPM packages can be found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en - ------------------------------------------------------------------------- All our advisories and generic update instructions can be viewed at http://distro.conectiva.com.br/atualizacoes/?idioma=en - ------------------------------------------------------------------------- Copyright (c) 2004 Conectiva Inc. http://www.conectiva.com - ------------------------------------------------------------------------- subscribe: conectiva-updates-subscribe@xxxxxxxxxxxxxxxxxxxxxxxxxxx unsubscribe: conectiva-updates-unsubscribe@xxxxxxxxxxxxxxxxxxxxxxxxxxx -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQFBj3Kg42jd0JmAcZARAgDUAKDkHA0wDki3F8kphf1lJ+KK9mLSKwCg8oXX Xzc3LeuVQZJlhQQw0Fn2gXw= =zInc -----END PGP SIGNATURE-----