Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.880583
Category:CentOS Local Security Checks
Title:CentOS Update for libtiff CESA-2010:0519 centos5 i386
Summary:The remote host is missing an update for the 'libtiff'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'libtiff'
package(s) announced via the referenced advisory.

Vulnerability Insight:
The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

Multiple integer overflow flaws, leading to a buffer overflow, were
discovered in libtiff. An attacker could use these flaws to create a
specially-crafted TIFF file that, when opened, would cause an application
linked against libtiff to crash or, possibly, execute arbitrary code.
(CVE-2010-1411)

Multiple input validation flaws were discovered in libtiff. An attacker
could use these flaws to create a specially-crafted TIFF file that, when
opened, would cause an application linked against libtiff to crash.
(CVE-2010-2481, CVE-2010-2483, CVE-2010-2595, CVE-2010-2597)

Red Hat would like to thank Apple Product Security for responsibly
reporting the CVE-2010-1411 flaw, who credit Kevin Finisterre of
digitalmunition.com for the discovery of the issue.

All libtiff users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. All running
applications linked against libtiff must be restarted for this update to
take effect.

Affected Software/OS:
libtiff on CentOS 5

Solution:
Please install the updated packages.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-1411
http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html
http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html
BugTraq ID: 40823
http://www.securityfocus.com/bid/40823
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043769.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043835.html
http://security.gentoo.org/glsa/glsa-201209-02.xml
http://marc.info/?l=oss-security&m=127731610612908&w=2
http://www.redhat.com/support/errata/RHSA-2010-0519.html
http://www.redhat.com/support/errata/RHSA-2010-0520.html
http://securitytracker.com/id?1024103
http://secunia.com/advisories/40181
http://secunia.com/advisories/40196
http://secunia.com/advisories/40220
http://secunia.com/advisories/40381
http://secunia.com/advisories/40478
http://secunia.com/advisories/40527
http://secunia.com/advisories/40536
http://secunia.com/advisories/50726
http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.596424
SuSE Security Announcement: SUSE-SR:2010:014 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html
http://www.ubuntu.com/usn/USN-954-1
http://www.vupen.com/english/advisories/2010/1435
http://www.vupen.com/english/advisories/2010/1481
http://www.vupen.com/english/advisories/2010/1512
http://www.vupen.com/english/advisories/2010/1638
http://www.vupen.com/english/advisories/2010/1731
http://www.vupen.com/english/advisories/2010/1761
Common Vulnerability Exposure (CVE) ID: CVE-2010-2481
40527
50726
ADV-2010-1761
GLSA-201209-02
RHSA-2010:0519
[oss-security] 20100623 CVE requests: LibTIFF
[oss-security] 20100624 Re: CVE requests: LibTIFF
http://marc.info/?l=oss-security&m=127736307002102&w=2
http://marc.info/?l=oss-security&m=127738540902757&w=2
[oss-security] 20100629 Re: CVE requests: LibTIFF
http://marc.info/?l=oss-security&m=127781315415896&w=2
[oss-security] 20100630 Re: CVE requests: LibTIFF
http://www.openwall.com/lists/oss-security/2010/06/30/22
[oss-security] 20100701 Re: CVE requests: LibTIFF
http://marc.info/?l=oss-security&m=127797353202873&w=2
http://bugzilla.maptools.org/show_bug.cgi?id=2210
Common Vulnerability Exposure (CVE) ID: CVE-2010-2483
40422
http://secunia.com/advisories/40422
http://bugzilla.maptools.org/show_bug.cgi?id=2216
https://bugs.launchpad.net/ubuntu/+source/tiff/+bug/591605
https://bugzilla.redhat.com/show_bug.cgi?id=603081
Common Vulnerability Exposure (CVE) ID: CVE-2010-2595
Debian Security Information: DSA-2552 (Google Search)
http://www.debian.org/security/2012/dsa-2552
Common Vulnerability Exposure (CVE) ID: CVE-2010-2597
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.