drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in LibTIFF (Aktualisierung)
Name: |
Mehrere Probleme in LibTIFF (Aktualisierung) |
|
ID: |
USN-3906-2 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 12.04 ESM |
|
Datum: |
Mo, 18. März 2019, 18:52 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7663
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18557
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10779
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6128
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17100
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12900
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17101
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1710 |
|
Applikationen: |
libtiff |
|
Update von: |
Mehrere Probleme in LibTIFF |
|
Originalnachricht |
--===============6366597415948034657== Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="=-HiGiLKuFHPMYK+D9hjZx"
--=-HiGiLKuFHPMYK+D9hjZx Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-3906-2 March 18, 2019
tiff vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 ESM
Summary:
LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.
Software Description: - tiff: Tag Image File Format (TIFF) library
Details:
USN-3906-1 and USN-3864-1 fixed several vulnerabilities in LibTIFF. This update provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04 ESM: libtiff-tools 3.9.5-2ubuntu1.12 libtiff4 3.9.5-2ubuntu1.12
In general, a standard system update will make all the necessary changes.
References: https://usn.ubuntu.com/usn/usn-3906-2 https://usn.ubuntu.com/usn/usn-3906-1 CVE-2018-10779, CVE-2018-12900, CVE-2018-1710, CVE-2018-17100, CVE-2018-17101, CVE-2018-18557, CVE-2019-6128, CVE-2019-7663 --=-HiGiLKuFHPMYK+D9hjZx Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2
iQIcBAABCAAGBQJcj6zYAAoJEEW851uECx9pwhAP/A/M8gT0X0VGsoix/lWWHxaw BvCIxyHZ2pLpl3o1NklWWsbys2EvjdKuQ2WsDVT9DVRKoHmynZ3ps4dGHlwQesdT 89KPcngbvysEM9qpD1Y659ec+iuKeFvYhxAmMJXQ8IMeLd/9Km6uW8TULbDSjqMw eEYwxnfR5lQRWD9ZqtdkIPinV9rZc7lrvQiTilYWVmu+jTQYgn4/3capq3QX1aVy pYvL0uCmnzs3IMuo0+0drjZIjgUUsdwePwcTUgxi8ViNryDPDrGc4SRFzXm9Iz4R cpZJfNqzc3HJsRLMlr4fNKcRco3KyNqDdjEZsgxS1u+Qh8gALkPmP2rVKqixHPd7 EA5aejmQ1lGWhtUhJHzE/R1vgBMjFm+J1wMlad7lVDIHefLlrVs83UfU3HsBiIdM pY7+himVNm8VKJRC8znRQhWCJet/bEsEcfphZijStifZtbvw1lngfH/IMzB5me2I IJCu8ZAp8nwLWWOH6FsX1a9w9HX4RG1Jt+WW+axb2zPlonBMz902cI1AwwJdbqHT 74pjzD3uKLpua54euZbMTuGOFv+dPZY5Ga7/EkZj+6ATI5KMaEFVdvR+ty2uF761 rLxRUiN3Rv4CnjJQyYDsKZprCwLvas8L4pzTR++oG6d0W3HIWLjAnpHkYC5i2RPg qXB8rj4xvZ8NoMDn9+U5 =VHQc -----END PGP SIGNATURE-----
--=-HiGiLKuFHPMYK+D9hjZx--
--===============6366597415948034657== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5 LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj dXJpdHktYW5ub3VuY2UK
--===============6366597415948034657==--
|
|
|
|