| Summary: | libtiff new security issue CVE-2013-4244 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | sysadmin-bugs, tmb, wilcal.int |
| Version: | 3 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/565084/ | ||
| Whiteboard: | MGA2TOO has_procedure MGA3-32-OK MGA3-64-OK MGA2-32-OK MGA2-64-OK | ||
| Source RPM: | libtiff-4.0.3-4.1.mga3.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2013-08-28 18:53:59 CEST
David Walser
2013-08-28 18:54:09 CEST
Version:
Cauldron =>
3
David Walser
2013-08-28 18:54:36 CEST
Severity:
normal =>
major Procedure: https://wiki.mageia.org/en/QA_procedure:Libtiff Whiteboard:
MGA2TOO =>
MGA2TOO has_procedure In VirtualBox and KDE Packages under test: libtiff bmp2tiff tiff2pdf tiffinfo libtiff-progs [root@localhost wilcal]# urpmi libtiff Package libtiff5-4.0.3-4.1.mga3.i586 is already installed [root@localhost Pictures]# urpmi libtiff-progs Package libtiff-progs-4.0.3-4.1.mga3.i586 is already installed bmp2tiff flag_b24.bmp flag_b24.tif works tiff2pdf flag_b24.tif > flag_b24.pdf works [wilcal@localhost Pictures]$ tiffinfo flag_b24.tif TIFF Directory at offset 0xaffe (45054) Image Width: 124 Image Length: 124 Bits/Sample: 8 Compression Scheme: PackBits Photometric Interpretation: RGB color Orientation: row 0 top, col 0 lhs Samples/Pixel: 3 Rows/Strip: 22 Planar Configuration: single image plane flag_b24.tif opens successfully with Gimp Install updates from core updates_testing [root@localhost wilcal]# urpmi libtiff Package libtiff5-4.0.3-4.2.mga3.i586 is already installed [root@localhost wilcal]# urpmi libtiff-progs Package libtiff-progs-4.0.3-4.2.mga3.i586 is already installed [wilcal@localhost Pictures]$ bmp2tiff flag_b24.bmp flag_b24.tif works [wilcal@localhost Pictures]$ tiff2pdf flag_b24.tif > flag_b24.pdf works [wilcal@localhost Pictures]$ tiffinfo flag_b24.tif TIFF Directory at offset 0xaffe (45054) Image Width: 124 Image Length: 124 Bits/Sample: 8 Compression Scheme: PackBits Photometric Interpretation: RGB color Orientation: row 0 top, col 0 lhs Samples/Pixel: 3 Rows/Strip: 22 Planar Configuration: single image plane Test platform: Intel Core i7-2600K Sandy Bridge 3.4GHz GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB RTL8111/8168B PCI Express 1Gbit Ethernet DRAM 16GB (4 x 4GB) VirtualBox 4.2.16-1.mga3.x86_64.rpm CC:
(none) =>
wilcal.int In VirtualBox and KDE [root@localhost wilcal]# urpmi libtiff Package lib64tiff5-4.0.3-4.1.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi libtiff-progs Package libtiff-progs-4.0.3-4.1.mga3.x86_64 is already installed [wilcal@localhost Pictures]$ bmp2tiff flag_b24.bmp flag_b24.tif works [wilcal@localhost Pictures]$ tiff2pdf flag_b24.tif > flag_b24.pdf works [wilcal@localhost Pictures]$ tiffinfo flag_b24.tif TIFF Directory at offset 0xaffe (45054) Image Width: 124 Image Length: 124 Bits/Sample: 8 Compression Scheme: PackBits Photometric Interpretation: RGB color Orientation: row 0 top, col 0 lhs Samples/Pixel: 3 Rows/Strip: 22 Planar Configuration: single image plane Install updates from core updates_testing [root@localhost wilcal]# urpmi libtiff Package lib64tiff5-4.0.3-4.2.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi libtiff-progs Package libtiff-progs-4.0.3-4.2.mga3.x86_64 is already installed [wilcal@localhost Pictures]$ bmp2tiff flag_b24.bmp flag_b24.tif works [wilcal@localhost Pictures]$ tiff2pdf flag_b24.tif > flag_b24.pdf works [wilcal@localhost Pictures]$ tiffinfo flag_b24.tif TIFF Directory at offset 0xaffe (45054) Image Width: 124 Image Length: 124 Bits/Sample: 8 Compression Scheme: PackBits Photometric Interpretation: RGB color Orientation: row 0 top, col 0 lhs Samples/Pixel: 3 Rows/Strip: 22 Planar Configuration: single image plane Whiteboard:
MGA2TOO has_procedure MGA3-32-OK =>
MGA2TOO has_procedure MGA3-32-OK MGA3-64-OK In VirtualBox and KDE Packages under test: libtiff bmp2tiff tiff2pdf tiffinfo libtiff-progs [root@localhost wilcal]# urpmi libtiff Package libtiff5-4.0.1-2.7.mga2.i586 is already installed [root@localhost wilcal]# urpmi libtiff-progs Package libtiff-progs-4.0.1-2.7.mga2.i586 is already installed [wilcal@localhost Pictures]$ bmp2tiff flag_b24.bmp flag_b24.tif works [wilcal@localhost Pictures]$ tiff2pdf flag_b24.tif > flag_b24.pdf works [wilcal@localhost Pictures]$ tiffinfo flag_b24.tif TIFF Directory at offset 0xaffe (45054) Image Width: 124 Image Length: 124 Bits/Sample: 8 Compression Scheme: PackBits Photometric Interpretation: RGB color Orientation: row 0 top, col 0 lhs Samples/Pixel: 3 Rows/Strip: 22 Planar Configuration: single image plane Install updates from core updates_testing [root@localhost Pictures]# urpmi libtiff Package libtiff5-4.0.1-2.8.mga2.i586 is already installed [root@localhost Pictures]# urpmi libtiff-progs Package libtiff-progs-4.0.1-2.8.mga2.i586 is already installed [wilcal@localhost Pictures]$ bmp2tiff flag_b24.bmp flag_b24.tif works [wilcal@localhost Pictures]$ tiff2pdf flag_b24.tif > flag_b24.pdf works [wilcal@localhost Pictures]$ tiffinfo flag_b24.tif TIFF Directory at offset 0xaffe (45054) Image Width: 124 Image Length: 124 Bits/Sample: 8 Compression Scheme: PackBits Photometric Interpretation: RGB color Orientation: row 0 top, col 0 lhs Samples/Pixel: 3 Rows/Strip: 22 Planar Configuration: single image plane Test platform: Intel Core i7-2600K Sandy Bridge 3.4GHz GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB RTL8111/8168B PCI Express 1Gbit Ethernet DRAM 16GB (4 x 4GB) VirtualBox 4.2.16-1.mga3.x86_64.rpm Whiteboard:
MGA2TOO has_procedure MGA3-32-OK MGA3-64-OK =>
MGA2TOO has_procedure MGA3-32-OK MGA3-64-OK MGA2-32-OK In VirtualBox and KDE Packages under test: libtiff bmp2tiff tiff2pdf tiffinfo libtiff-progs [root@localhost Pictures]# urpmi libtiff Package lib64tiff5-4.0.1-2.7.mga2.x86_64 is already installed [root@localhost Pictures]# urpmi libtiff-progs Package libtiff-progs-4.0.1-2.7.mga2.x86_64 is already installed [wilcal@localhost Pictures]$ bmp2tiff flag_b24.bmp flag_b24.tif works [wilcal@localhost Pictures]$ tiff2pdf flag_b24.tif > flag_b24.pdf works [wilcal@localhost Pictures]$ tiffinfo flag_b24.tif TIFF Directory at offset 0xaffe (45054) Image Width: 124 Image Length: 124 Bits/Sample: 8 Compression Scheme: PackBits Photometric Interpretation: RGB color Orientation: row 0 top, col 0 lhs Samples/Pixel: 3 Rows/Strip: 22 Planar Configuration: single image plane Install updates from core updates_testing [root@localhost Pictures]# urpmi libtiff Package lib64tiff5-4.0.1-2.8.mga2.x86_64 is already installed [root@localhost Pictures]# urpmi libtiff-progs Package libtiff-progs-4.0.1-2.8.mga2.x86_64 is already installed [wilcal@localhost Pictures]$ bmp2tiff flag_b24.bmp flag_b24.tif works [wilcal@localhost Pictures]$ tiff2pdf flag_b24.tif > flag_b24.pdf works [wilcal@localhost Pictures]$ tiffinfo flag_b24.tif TIFF Directory at offset 0xaffe (45054) Image Width: 124 Image Length: 124 Bits/Sample: 8 Compression Scheme: PackBits Photometric Interpretation: RGB color Orientation: row 0 top, col 0 lhs Samples/Pixel: 3 Rows/Strip: 22 Planar Configuration: single image plane Test platform: Intel Core i7-2600K Sandy Bridge 3.4GHz GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB RTL8111/8168B PCI Express 1Gbit Ethernet DRAM 16GB (4 x 4GB) VirtualBox 4.2.16-1.mga3.x86_64.rpm Keywords:
(none) =>
validated_update Testing complete mga2/3 32 & 64 Validating the update. Could someone from the sysadmin team push 11099.adv to updates. Thanks 11099.adv doesn't appear to have been uploaded yet. I'll remove the validated tag and let Dave or Claire re-add it when it's uploaded. Keywords:
validated_update =>
(none) (In reply to David Walser from comment #7) > 11099.adv doesn't appear to have been uploaded yet. That's cuz I'm too quick. :-)) Thanks Well done William. Advisory uploaded. Thanks
claire robinson
2013-08-28 22:24:27 CEST
Keywords:
(none) =>
validated_update Update pushed: http://advisories.mageia.org/MGASA-2013-0267.html Status:
NEW =>
RESOLVED |