Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in tiff
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in tiff
ID: USN-1120-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 10.10
Datum: Do, 21. April 2011, 16:55
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5022
Applikationen: libtiff

Originalnachricht


--===============8934775994078095020==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature"; boundary="=-Ugf7Eo/Qrg4fHJyrHpPe"


--=-Ugf7Eo/Qrg4fHJyrHpPe
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1120-1
April 21, 2011

tiff vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.10
- Ubuntu 10.04 LTS

Summary:

The TIFF library could be made to run programs as your login if it opened a
specially crafted file.

Software Description:
- tiff: TIFF manipulation and conversion tools

Details:

It was discovered that the TIFF library incorrectly handled certain JPEG
data. If a user or automated system were tricked into opening a specially
crafted TIFF image, a remote attacker could execute arbitrary code with
user privileges, or crash the application, leading to a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.10:
libtiff4 3.9.4-2ubuntu0.4

Ubuntu 10.04 LTS:
libtiff4 3.9.2-2ubuntu0.7

After a standard system update you need to restart your session to make
all the necessary changes.

References:
CVE-2009-5022

Package Information:
https://launchpad.net/ubuntu/+source/tiff/3.9.4-2ubuntu0.4
https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.7



--Þgf7Eo/Qrg4fHJyrHpPe
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJNsDNeAAoJEGVp2FWnRL6TYSkQAJxtjHDSGpkcfTXDMixlsbhC
QMLEFd01mkr8ld2IuO6TRUjnvz2FYW8AVlX69YHTanb1F9crVgJdaAOFnJXa/mPN
YhB5Jk9BaXgcu2+6PxgPEbELTQuL4C4asowqmXLJAoelGp0HpYmXnTlx+JSFlqcx
105ltrbfLzVd3rJ5/HPaZCdPb8c0eK7WAyIcZDw0KfEecIoLKQmFGuQ8YTEqUexH
4rociu5LmrxUzsnLgodkR0E+93wqzjBy97XAx5/5ANsZwr4JlevZPbzPQaQn+s++
e7h7YaUXEO3g376pMI+Nner0i10VuqDG608ICjQMh7Aq2c2EVVgiacz6Yr0LpDyu
1HiFvYBf2lw5L+i7MV6/RBg53XkZEfHaHx1F6IQ36HgsJpHJPZwFBWwucxALwj/s
7QtNQ4NQ5WrEM9HO2JD0fJajZ6oZjj8G6/txYjIaxC8NIRbgnrZkyRpM6vrFgy93
eti0PWSB7eddg3dvzpSangmd/4J9jRcuS910ia6DMr+0cUkXRpzL/Qft+Dh41Nun
mji0OcFSxOfgYeM7inE3s8Cf9FP0mevIvPq1c/Y4nSLWGr1X9Y0JBEuzxoB5GTaO
G3b8HfgunS9JOqWh/FHQhIGX68aLRAFXnG3CJHp1jdMAmZN3n7mu6jTZl0G2TSBK
hvQRpOBDIfx5Nq+IKVND
=HPa0
-----END PGP SIGNATURE-----

--=-Ugf7Eo/Qrg4fHJyrHpPe--



--===============8934775994078095020==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============8934775994078095020==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung