SB2011032801 - Multiple vulnerabilities in LibTIFF
Published: March 28, 2011 Updated: May 21, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Heap-based buffer overflow (CVE-ID: CVE-2009-5022)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5. A remote attacker can use a crafted TIFF file. to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
2) Input validation error (CVE-ID: CVE-2010-4665)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Integer overflow in the ReadDirectory function in tiffdump.c in tiffdump in LibTIFF before 3.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF file containing a directory data structure with many directory entries.
3) Heap-based buffer overflow (CVE-ID: CVE-2011-1167)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier. A remote attacker can use crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value. to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
Install update from vendor's website.
References
- http://bugzilla.maptools.org/show_bug.cgi?id=1999
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058478.html
- http://openwall.com/lists/oss-security/2011/04/12/10
- http://secunia.com/advisories/44271
- http://secunia.com/advisories/50726
- http://security.gentoo.org/glsa/glsa-201209-02.xml
- http://securitytracker.com/id?1025380
- http://www.debian.org/security/2011/dsa-2256
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:078
- http://www.redhat.com/support/errata/RHSA-2011-0452.html
- http://www.remotesensing.org/libtiff/v3.9.5.html
- http://www.securityfocus.com/bid/47338
- http://www.ubuntu.com/usn/USN-1120-1
- http://www.vupen.com/english/advisories/2011/1014
- http://www.vupen.com/english/advisories/2011/1082
- https://bugzilla.redhat.com/show_bug.cgi?id=695885
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66774
- http://bugzilla.maptools.org/show_bug.cgi?id=2218
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
- http://ubuntu.com/usn/usn-1416-1
- http://www.debian.org/security/2012/dsa-2552
- https://bugzilla.redhat.com/show_bug.cgi?id=695887
- http://blackberry.com/btsc/KB27244
- http://bugzilla.maptools.org/show_bug.cgi?id=2300
- http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html
- http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057763.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057840.html
- http://secunia.com/advisories/43900
- http://secunia.com/advisories/43934
- http://secunia.com/advisories/43974
- http://secunia.com/advisories/44117
- http://secunia.com/advisories/44135
- http://securityreason.com/securityalert/8165
- http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.587820
- http://support.apple.com/kb/HT5130
- http://support.apple.com/kb/HT5281
- http://support.apple.com/kb/HT5503
- http://ubuntu.com/usn/usn-1102-1
- http://www.debian.org/security/2011/dsa-2210
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:064
- http://www.osvdb.org/71256
- http://www.redhat.com/support/errata/RHSA-2011-0392.html
- http://www.securityfocus.com/archive/1/517101/100/0/threaded
- http://www.securityfocus.com/bid/46951
- http://www.securitytracker.com/id?1025257
- http://www.vupen.com/english/advisories/2011/0795
- http://www.vupen.com/english/advisories/2011/0845
- http://www.vupen.com/english/advisories/2011/0859
- http://www.vupen.com/english/advisories/2011/0860
- http://www.vupen.com/english/advisories/2011/0905
- http://www.vupen.com/english/advisories/2011/0930
- http://www.vupen.com/english/advisories/2011/0960
- http://www.zerodayinitiative.com/advisories/ZDI-11-107
- https://bugzilla.redhat.com/show_bug.cgi?id=684939
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66247