Bug 8087 - libtiff new security issue CVE-2012-4564
: libtiff new security issue CVE-2012-4564
Status: RESOLVED FIXED
Product: Mageia
Classification: Unclassified
Component: Security
: 2
: i586 Linux
: Normal Severity: major
: ---
Assigned To: QA Team
:
: http://lwn.net/Vulnerabilities/525259/
: MGA1TOO has_procedure mga2-32-OK mga2...
: validated_update
:
:
  Show dependency treegraph
 
Reported: 2012-11-15 19:41 CET by David Walser
Modified: 2012-11-17 17:34 CET (History)
2 users (show)

See Also:
Source RPM: libtiff-4.0.1-2.3.mga1.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2012-11-15 19:41:01 CET
Ubuntu has issued an advisory today (November 15):
http://www.ubuntu.com/usn/usn-1631-1/

Patched packages uploaded for Mageia 1, Mageia 2, and Cauldron.

Advisory:
========================

Updated libtiff packages fix security vulnerability:

ppm2tiff does not check the return value of the TIFFScanlineSize function,
which allows remote attackers to cause a denial of service (crash) and
possibly execute arbitrary code via a crafted PPM image that triggers an
integer overflow, a zero-memory allocation, and a heap-based buffer overflow
(CVE-2012-4564).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4564
http://www.ubuntu.com/usn/usn-1631-1/
========================

Updated packages in core/updates_testing:
========================
libtiff-progs-3.9.5-1.7.mga1.x86_64.rpm
libtiff3-3.9.5-1.7.mga1
libtiff-devel-3.9.5-1.7.mga1
libtiff-static-devel-3.9.5-1.7.mga1
libtiff-progs-4.0.1-2.4.mga2
libtiff5-4.0.1-2.4.mga2
libtiff-devel-4.0.1-2.4.mga2
libtiff-static-devel-4.0.1-2.4.mga2

from SRPMS:
libtiff-3.9.5-1.7.mga1.src.rpm
libtiff-4.0.1-2.4.mga2.src.rpm
Comment 1 Samuel Verschelde 2012-11-16 13:24:32 CET
Procedure: https://wiki.mageia.org/en/QA_procedure:Libtiff
Comment 2 claire robinson 2012-11-16 16:05:42 CET
Testing complete mga2 32 & 64
Comment 3 claire robinson 2012-11-16 16:17:27 CET
Testing complete mga1 32 & 64

Validating

Advisory & srpms in comment 0

Could sysadmin please push to updates

Thanks!
Comment 4 Thomas Backlund 2012-11-17 17:34:12 CET
Update pushed:
https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0332

Note You need to log in before you can comment on or make changes to this bug.