Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.812582
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-3602-1)
Summary:The remote host is missing an update for the 'tiff' package(s) announced via the USN-3602-1 advisory.
Description:Summary:
The remote host is missing an update for the 'tiff' package(s) announced via the USN-3602-1 advisory.

Vulnerability Insight:
It was discovered that LibTIFF incorrectly handled certain malformed
images. If a user or automated system were tricked into opening a specially
crafted image, a remote attacker could crash the application, leading to a
denial of service, or possibly execute arbitrary code with user privileges.

Affected Software/OS:
'tiff' package(s) on Ubuntu 14.04, Ubuntu 16.04.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-10266
BugTraq ID: 97115
http://www.securityfocus.com/bid/97115
Debian Security Information: DSA-3844 (Google Search)
http://www.debian.org/security/2017/dsa-3844
https://blogs.gentoo.org/ago/2017/01/01/libtiff-multiple-divide-by-zero
https://github.com/vadz/libtiff/commit/438274f938e046d33cb0e1230b41da32ffe223e1
https://usn.ubuntu.com/3602-1/
Common Vulnerability Exposure (CVE) ID: CVE-2016-10267
BugTraq ID: 97117
http://www.securityfocus.com/bid/97117
https://security.gentoo.org/glsa/201709-27
https://github.com/vadz/libtiff/commit/43bc256d8ae44b92d2734a3c5bc73957a4d7c1ec
Common Vulnerability Exposure (CVE) ID: CVE-2016-10268
BugTraq ID: 97202
http://www.securityfocus.com/bid/97202
https://blogs.gentoo.org/ago/2017/01/01/libtiff-multiple-heap-based-buffer-overflow/
https://github.com/vadz/libtiff/commit/5397a417e61258c69209904e652a1f409ec3b9df
Common Vulnerability Exposure (CVE) ID: CVE-2016-10269
BugTraq ID: 97201
http://www.securityfocus.com/bid/97201
https://github.com/Hack-Me/Pocs_for_Multi_Versions/tree/main/CVE-2016-10269
https://github.com/vadz/libtiff/commit/1044b43637fa7f70fb19b93593777b78bd20da86
Common Vulnerability Exposure (CVE) ID: CVE-2016-10371
Common Vulnerability Exposure (CVE) ID: CVE-2017-10688
BugTraq ID: 99359
http://www.securityfocus.com/bid/99359
Debian Security Information: DSA-3903 (Google Search)
http://www.debian.org/security/2017/dsa-3903
https://www.exploit-db.com/exploits/42299/
http://bugzilla.maptools.org/show_bug.cgi?id=2712
Common Vulnerability Exposure (CVE) ID: CVE-2017-11335
Debian Security Information: DSA-4100 (Google Search)
https://www.debian.org/security/2018/dsa-4100
http://bugzilla.maptools.org/show_bug.cgi?id=2715
Common Vulnerability Exposure (CVE) ID: CVE-2017-12944
https://usn.ubuntu.com/3606-1/
Common Vulnerability Exposure (CVE) ID: CVE-2017-13726
BugTraq ID: 100524
http://www.securityfocus.com/bid/100524
http://bugzilla.maptools.org/show_bug.cgi?id=2727
Common Vulnerability Exposure (CVE) ID: CVE-2017-13727
http://bugzilla.maptools.org/show_bug.cgi?id=2728
Common Vulnerability Exposure (CVE) ID: CVE-2017-18013
BugTraq ID: 102345
http://www.securityfocus.com/bid/102345
https://lists.debian.org/debian-lts-announce/2018/01/msg00033.html
https://lists.debian.org/debian-lts-announce/2018/01/msg00034.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-7592
BugTraq ID: 97510
http://www.securityfocus.com/bid/97510
http://bugzilla.maptools.org/show_bug.cgi?id=2658
Common Vulnerability Exposure (CVE) ID: CVE-2017-7593
BugTraq ID: 97502
http://www.securityfocus.com/bid/97502
http://bugzilla.maptools.org/show_bug.cgi?id=2651
Common Vulnerability Exposure (CVE) ID: CVE-2017-7594
BugTraq ID: 97503
http://www.securityfocus.com/bid/97503
http://bugzilla.maptools.org/show_bug.cgi?id=2659
Common Vulnerability Exposure (CVE) ID: CVE-2017-7595
BugTraq ID: 97501
http://www.securityfocus.com/bid/97501
https://blogs.gentoo.org/ago/2017/04/01/libtiff-divide-by-zero-in-jpegsetupencode-tiff_jpeg-c
Common Vulnerability Exposure (CVE) ID: CVE-2017-7596
BugTraq ID: 97506
http://www.securityfocus.com/bid/97506
https://blogs.gentoo.org/ago/2017/04/01/libtiff-multiple-ubsan-crashes
Common Vulnerability Exposure (CVE) ID: CVE-2017-7597
BugTraq ID: 97504
http://www.securityfocus.com/bid/97504
Common Vulnerability Exposure (CVE) ID: CVE-2017-7598
BugTraq ID: 97499
http://www.securityfocus.com/bid/97499
Common Vulnerability Exposure (CVE) ID: CVE-2017-7599
BugTraq ID: 97505
http://www.securityfocus.com/bid/97505
BugTraq ID: 97508
http://www.securityfocus.com/bid/97508
Common Vulnerability Exposure (CVE) ID: CVE-2017-7600
Common Vulnerability Exposure (CVE) ID: CVE-2017-7601
BugTraq ID: 97511
http://www.securityfocus.com/bid/97511
Common Vulnerability Exposure (CVE) ID: CVE-2017-7602
BugTraq ID: 97500
http://www.securityfocus.com/bid/97500
Common Vulnerability Exposure (CVE) ID: CVE-2017-9403
Common Vulnerability Exposure (CVE) ID: CVE-2017-9404
Common Vulnerability Exposure (CVE) ID: CVE-2017-9815
BugTraq ID: 99235
http://www.securityfocus.com/bid/99235
http://bugzilla.maptools.org/show_bug.cgi?id=2682
http://somevulnsofadlab.blogspot.jp/2017/06/libtiffmemory-leak-in-tiffmalloc.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-9936
BugTraq ID: 99300
http://www.securityfocus.com/bid/99300
https://www.exploit-db.com/exploits/42300/
http://bugzilla.maptools.org/show_bug.cgi?id=2706
Common Vulnerability Exposure (CVE) ID: CVE-2018-5784
Debian Security Information: DSA-4349 (Google Search)
https://www.debian.org/security/2018/dsa-4349
http://bugzilla.maptools.org/show_bug.cgi?id=2772
https://lists.debian.org/debian-lts-announce/2018/05/msg00022.html
https://lists.debian.org/debian-lts-announce/2018/07/msg00002.html
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.