DSA-2256-1 tiff -- buffer overflow

Related Vulnerabilities: CVE-2009-5022  

Tavis Ormandy discovered that the Tag Image File Format (TIFF) library is vulnerable to a buffer overflow triggered by a crafted OJPEG file which allows for a crash and potentially execution of arbitrary code. The oldstable distribution (lenny) is not affected by this problem. For the stable distribution (squeeze), this problem has been fixed in version 3.9.4-5+squeeze2. For the testing distribution (wheezy) and unstable distribution (sid), this problem has been fixed in version 3.9.5-1. We recommend that you upgrade your tiff packages.

Debian Security Advisory

DSA-2256-1 tiff -- buffer overflow

Date Reported:
09 Jun 2011
Affected Packages:
tiff
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 624287.
In Mitre's CVE dictionary: CVE-2009-5022.
More information:

Tavis Ormandy discovered that the Tag Image File Format (TIFF) library is vulnerable to a buffer overflow triggered by a crafted OJPEG file which allows for a crash and potentially execution of arbitrary code.

The oldstable distribution (lenny) is not affected by this problem.

For the stable distribution (squeeze), this problem has been fixed in version 3.9.4-5+squeeze2.

For the testing distribution (wheezy) and unstable distribution (sid), this problem has been fixed in version 3.9.5-1.

We recommend that you upgrade your tiff packages.