Bug 3985 - libtiff missing security update for CVE-2011-0191
Summary: libtiff missing security update for CVE-2011-0191
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard:
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2012-01-01 06:10 CET by David Walser
Modified: 2012-01-09 15:12 CET (History)
6 users (show)

See Also:
Source RPM: libtiff-3.9.5-1.mga1.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2012-01-01 06:10:36 CET
Mandriva issued this advisory on April 4:
http://lists.mandriva.com/security-announce/2011-04/msg00006.php

The other CVE was fixed in 3.9.5.
Comment 1 Manuel Hiebel 2012-01-01 13:11:20 CET
Hi, thanks for reporting this bug.
As there is no maintainer for this package I added the committers in CC.

(Please set the status to 'assigned' if you are working on it)

CC: (none) => fundawang, pterjan

Comment 2 David Walser 2012-01-01 13:26:10 CET
Just a note that Mandriva shipped this patch with the libtiff 3.9.5 in Mandriva 2011.
Comment 3 D Morgan 2012-01-03 01:49:05 CET
pushed in the BS for updates_testing

CC: (none) => dmorganec
Assignee: bugsquad => qa-bugs

Comment 4 David Walser 2012-01-03 22:46:04 CET
Tested on i586 by opening a TIFF file in the GIMP which uses libtiff.  Looks good.
Comment 5 David GEIGER 2012-01-09 10:21:38 CET
Tested complete the srpm libtiff-3.9.5-1.1.mga1.src.rpm on Mageia release 1 (Official) for x86_64 ,works too when I open a TIFF file with Gimp.

CC: (none) => geiger.david68210

Comment 6 claire robinson 2012-01-09 12:59:24 CET
Validating

Advisory
---------------
This update corrects CVE-2011-0191

Buffer overflow in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image with JPEG encoding. 

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0191
---------------

SRPM: libtiff-3.9.5-1.1.mga1.src.rpm

Could sysadmin please push from core/updates_testing to core/updates

Thankyou!

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs
Hardware: i586 => All

Comment 7 Thomas Backlund 2012-01-09 15:12:45 CET
update pushed

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.