![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.890880 |
Category: | Debian Local Security Checks |
Title: | Debian: Security Advisory (DLA-880-1) |
Summary: | The remote host is missing an update for the Debian 'tiff3' package(s) announced via the DLA-880-1 advisory. |
Description: | Summary: The remote host is missing an update for the Debian 'tiff3' package(s) announced via the DLA-880-1 advisory. Vulnerability Insight: tiff3 is affected by multiple issues that can result at least in denial of services of applications using libtiff4. Crafted TIFF files can be provided to trigger: abort() calls via failing assertions, buffer overruns (both in read and write mode). CVE-2015-8781 tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of samples per pixel in a LogL compressed TIFF image. CVE-2015-8782 tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image. CVE-2015-8783 tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image. CVE-2015-8784 The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image. CVE-2016-9533 tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers. CVE-2016-9534 tif_write.c in libtiff 4.0.6 has an issue in the error code path of TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp members. CVE-2016-9535 tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. For Debian 7 Wheezy, these problems have been fixed in version 3.9.6-11+deb7u4. We recommend that you upgrade your tiff3 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: [link moved to references] Affected Software/OS: 'tiff3' package(s) on Debian 7. Solution: Please install the updated package(s). CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2015-8781 BugTraq ID: 81730 http://www.securityfocus.com/bid/81730 Debian Security Information: DSA-3467 (Google Search) http://www.debian.org/security/2016/dsa-3467 https://security.gentoo.org/glsa/201701-16 http://www.openwall.com/lists/oss-security/2016/01/24/3 http://www.openwall.com/lists/oss-security/2016/01/24/7 RedHat Security Advisories: RHSA-2016:1546 http://rhn.redhat.com/errata/RHSA-2016-1546.html RedHat Security Advisories: RHSA-2016:1547 http://rhn.redhat.com/errata/RHSA-2016-1547.html SuSE Security Announcement: openSUSE-SU-2016:0405 (Google Search) http://lists.opensuse.org/opensuse-updates/2016-02/msg00058.html SuSE Security Announcement: openSUSE-SU-2016:0414 (Google Search) http://lists.opensuse.org/opensuse-updates/2016-02/msg00064.html http://www.ubuntu.com/usn/USN-2939-1 Common Vulnerability Exposure (CVE) ID: CVE-2015-8782 Common Vulnerability Exposure (CVE) ID: CVE-2015-8783 Common Vulnerability Exposure (CVE) ID: CVE-2015-8784 BugTraq ID: 81696 http://www.securityfocus.com/bid/81696 http://www.openwall.com/lists/oss-security/2016/01/24/4 http://www.openwall.com/lists/oss-security/2016/01/24/8 Common Vulnerability Exposure (CVE) ID: CVE-2016-9533 BugTraq ID: 94484 http://www.securityfocus.com/bid/94484 BugTraq ID: 94742 http://www.securityfocus.com/bid/94742 Debian Security Information: DSA-3762 (Google Search) http://www.debian.org/security/2017/dsa-3762 RedHat Security Advisories: RHSA-2017:0225 http://rhn.redhat.com/errata/RHSA-2017-0225.html Common Vulnerability Exposure (CVE) ID: CVE-2016-9534 BugTraq ID: 94743 http://www.securityfocus.com/bid/94743 Common Vulnerability Exposure (CVE) ID: CVE-2016-9535 BugTraq ID: 94744 http://www.securityfocus.com/bid/94744 Debian Security Information: DSA-3844 (Google Search) http://www.debian.org/security/2017/dsa-3844 |
Copyright | Copyright (C) 2018 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |