DSA-2447-1 tiff -- integer overflow

Related Vulnerabilities: CVE-2012-1173  

Alexander Gavrun discovered an integer overflow in the TIFF library in the parsing of the TileSize entry, which could result in the execution of arbitrary code if a malformed image is opened. For the stable distribution (squeeze), this problem has been fixed in version 3.9.4-5+squeeze4. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your tiff packages.

Debian Security Advisory

DSA-2447-1 tiff -- integer overflow

Date Reported:
04 Apr 2012
Affected Packages:
tiff
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2012-1173.
More information:

Alexander Gavrun discovered an integer overflow in the TIFF library in the parsing of the TileSize entry, which could result in the execution of arbitrary code if a malformed image is opened.

For the stable distribution (squeeze), this problem has been fixed in version 3.9.4-5+squeeze4.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your tiff packages.