tiff vulnerabilities

Related Vulnerabilities: CVE-2006-2024   CVE-2006-2025   CVE-2006-2026   CVE-2006-2120  

Tavis Ormandy and Andrey Kiselev discovered that libtiff did not sufficiently verify the validity of TIFF files. By tricking an user into opening a specially crafted TIFF file with any application that uses libtiff, an attacker could exploit this to crash the application or even execute arbitrary code with the application’s privileges.

The problem can be corrected by updating your system to the following package versions:

4 May 2006

tiff vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 5.10
  • Ubuntu 5.04

Software Description

Details

Tavis Ormandy and Andrey Kiselev discovered that libtiff did not sufficiently verify the validity of TIFF files. By tricking an user into opening a specially crafted TIFF file with any application that uses libtiff, an attacker could exploit this to crash the application or even execute arbitrary code with the application’s privileges.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 5.10
libtiff4
Ubuntu 5.04
libtiff4

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

References