drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in tiff
Name: |
Ausführen beliebiger Kommandos in tiff |
|
ID: |
USN-1120-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 10.04 LTS, Ubuntu 10.10 |
|
Datum: |
Do, 21. April 2011, 16:55 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5022 |
|
Applikationen: |
libtiff |
|
Originalnachricht |
--===============8934775994078095020== Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-Ugf7Eo/Qrg4fHJyrHpPe"
--=-Ugf7Eo/Qrg4fHJyrHpPe Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-1120-1 April 21, 2011
tiff vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.10 - Ubuntu 10.04 LTS
Summary:
The TIFF library could be made to run programs as your login if it opened a specially crafted file.
Software Description: - tiff: TIFF manipulation and conversion tools
Details:
It was discovered that the TIFF library incorrectly handled certain JPEG data. If a user or automated system were tricked into opening a specially crafted TIFF image, a remote attacker could execute arbitrary code with user privileges, or crash the application, leading to a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 10.10: libtiff4 3.9.4-2ubuntu0.4
Ubuntu 10.04 LTS: libtiff4 3.9.2-2ubuntu0.7
After a standard system update you need to restart your session to make all the necessary changes.
References: CVE-2009-5022
Package Information: https://launchpad.net/ubuntu/+source/tiff/3.9.4-2ubuntu0.4 https://launchpad.net/ubuntu/+source/tiff/3.9.2-2ubuntu0.7
--Þgf7Eo/Qrg4fHJyrHpPe Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux)
iQIcBAABCgAGBQJNsDNeAAoJEGVp2FWnRL6TYSkQAJxtjHDSGpkcfTXDMixlsbhC QMLEFd01mkr8ld2IuO6TRUjnvz2FYW8AVlX69YHTanb1F9crVgJdaAOFnJXa/mPN YhB5Jk9BaXgcu2+6PxgPEbELTQuL4C4asowqmXLJAoelGp0HpYmXnTlx+JSFlqcx 105ltrbfLzVd3rJ5/HPaZCdPb8c0eK7WAyIcZDw0KfEecIoLKQmFGuQ8YTEqUexH 4rociu5LmrxUzsnLgodkR0E+93wqzjBy97XAx5/5ANsZwr4JlevZPbzPQaQn+s++ e7h7YaUXEO3g376pMI+Nner0i10VuqDG608ICjQMh7Aq2c2EVVgiacz6Yr0LpDyu 1HiFvYBf2lw5L+i7MV6/RBg53XkZEfHaHx1F6IQ36HgsJpHJPZwFBWwucxALwj/s 7QtNQ4NQ5WrEM9HO2JD0fJajZ6oZjj8G6/txYjIaxC8NIRbgnrZkyRpM6vrFgy93 eti0PWSB7eddg3dvzpSangmd/4J9jRcuS910ia6DMr+0cUkXRpzL/Qft+Dh41Nun mji0OcFSxOfgYeM7inE3s8Cf9FP0mevIvPq1c/Y4nSLWGr1X9Y0JBEuzxoB5GTaO G3b8HfgunS9JOqWh/FHQhIGX68aLRAFXnG3CJHp1jdMAmZN3n7mu6jTZl0G2TSBK hvQRpOBDIfx5Nq+IKVND =HPa0 -----END PGP SIGNATURE-----
--=-Ugf7Eo/Qrg4fHJyrHpPe--
--===============8934775994078095020== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============8934775994078095020==--
|
|
|
|