Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.123770
Category:Oracle Linux Local Security Checks
Title:Oracle: Security Advisory (ELSA-2012-1590)
Summary:The remote host is missing an update for the 'libtiff' package(s) announced via the ELSA-2012-1590 advisory.
Description:Summary:
The remote host is missing an update for the 'libtiff' package(s) announced via the ELSA-2012-1590 advisory.

Vulnerability Insight:
[3.9.4-9]
- Still more fixes to make test case for CVE-2012-5581 work on all platforms
Resolves: #885310

[3.9.4-8]
- Fix incomplete patch for CVE-2012-3401
- Add libtiff-tiffinfo-exif.patch so that our test case for CVE-2012-5581 works
with pre-4.0.2 libtiff
Resolves: #885310

[3.9.4-7]
- Add fixes for CVE-2012-3401, CVE-2012-4447, CVE-2012-4564, CVE-2012-5581
Resolves: #885310

Affected Software/OS:
'libtiff' package(s) on Oracle Linux 5, Oracle Linux 6.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-3401
49938
http://secunia.com/advisories/49938
50007
http://secunia.com/advisories/50007
50726
http://secunia.com/advisories/50726
54601
http://www.securityfocus.com/bid/54601
84090
http://osvdb.org/84090
DSA-2552
http://www.debian.org/security/2012/dsa-2552
GLSA-201209-02
http://security.gentoo.org/glsa/glsa-201209-02.xml
MDVSA-2012:127
http://www.mandriva.com/security/advisories?name=MDVSA-2012:127
RHSA-2012:1590
http://rhn.redhat.com/errata/RHSA-2012-1590.html
USN-1511-1
http://www.ubuntu.com/usn/USN-1511-1
[oss-security] 20120719 Re: tiff2pdf: Heap-based buffer overflow due to improper initialization of T2P context struct pointer
http://www.openwall.com/lists/oss-security/2012/07/19/4
[oss-security] 20120719 tiff2pdf: Heap-based buffer overflow due to improper initialization of T2P context struct pointer
http://www.openwall.com/lists/oss-security/2012/07/19/1
http://libjpeg-turbo.svn.sourceforge.net/viewvc/libjpeg-turbo?view=revision&revision=830
http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf
https://bugzilla.redhat.com/attachment.cgi?id=596457
https://bugzilla.redhat.com/show_bug.cgi?id=837577
libtiff-t2preadtiffinit-bo(77088)
https://exchange.xforce.ibmcloud.com/vulnerabilities/77088
openSUSE-SU-2012:0955
http://lists.opensuse.org/opensuse-updates/2012-08/msg00011.html
Common Vulnerability Exposure (CVE) ID: CVE-2012-4447
51049
http://secunia.com/advisories/51049
55673
http://www.securityfocus.com/bid/55673
DSA-2561
http://www.debian.org/security/2012/dsa-2561
USN-1631-1
http://www.ubuntu.com/usn/USN-1631-1
[oss-security] 20120925 CVE Request: libtiff: Heap-buffer overflow when processing a TIFF image with PixarLog Compression
http://www.openwall.com/lists/oss-security/2012/09/25/9
[oss-security] 20120925 Re: CVE Request: libtiff: Heap-buffer overflow when processing a TIFF image with PixarLog Compression
http://www.openwall.com/lists/oss-security/2012/09/25/14
http://www.remotesensing.org/libtiff/v4.0.3.html
https://bugzilla.redhat.com/show_bug.cgi?id=860198
openSUSE-SU-2013:0187
http://lists.opensuse.org/opensuse-updates/2013-01/msg00076.html
Common Vulnerability Exposure (CVE) ID: CVE-2012-4564
51133
http://secunia.com/advisories/51133
56372
http://www.securityfocus.com/bid/56372
86878
http://www.osvdb.org/86878
DSA-2575
http://www.debian.org/security/2012/dsa-2575
[oss-security] 20121102 Re: libtiff: Missing return value check in ppm2tiff leading to heap-buffer overflow when reading a tiff file
http://www.openwall.com/lists/oss-security/2012/11/02/7
[oss-security] 20121102 libtiff: Missing return value check in ppm2tiff leading to heap-buffer overflow when reading a tiff file
http://www.openwall.com/lists/oss-security/2012/11/02/3
https://bugzilla.redhat.com/show_bug.cgi?id=871700
libtiff-ppm2tiff-bo(79750)
https://exchange.xforce.ibmcloud.com/vulnerabilities/79750
Common Vulnerability Exposure (CVE) ID: CVE-2012-5581
51491
http://secunia.com/advisories/51491
56715
http://www.securityfocus.com/bid/56715
DSA-2589
http://www.debian.org/security/2012/dsa-2589
USN-1655-1
http://www.ubuntu.com/usn/USN-1655-1
[oss-security] 20121128 libtiff: Stack based buffer overflow when handling DOTRANGE tags
http://www.openwall.com/lists/oss-security/2012/11/28/1
https://bugzilla.redhat.com/show_bug.cgi?id=867235
libtiff-dotrange-bo(80339)
https://exchange.xforce.ibmcloud.com/vulnerabilities/80339
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.