Scientific Linux Security Update : libtiff on SL5.x, SL6.x i386/x86_64 (20121218)

medium Nessus Plugin ID 63314

Synopsis

The remote Scientific Linux host is missing one or more security updates.

Description

A heap-based buffer overflow flaw was found in the way libtiff processed certain TIFF images using the Pixar Log Format encoding. An attacker could create a specially crafted TIFF file that, when opened, could cause an application using libtiff to crash or, possibly, execute arbitrary code with the privileges of the user running the application. (CVE-2012-4447)

A stack-based buffer overflow flaw was found in the way libtiff handled DOTRANGE tags. An attacker could use this flaw to create a specially crafted TIFF file that, when opened, would cause an application linked against libtiff to crash or, possibly, execute arbitrary code. (CVE-2012-5581)

A heap-based buffer overflow flaw was found in the tiff2pdf tool. An attacker could use this flaw to create a specially crafted TIFF file that would cause tiff2pdf to crash or, possibly, execute arbitrary code. (CVE-2012-3401)

A missing return value check flaw, leading to a heap-based buffer overflow, was found in the ppm2tiff tool. An attacker could use this flaw to create a specially crafted PPM (Portable Pixel Map) file that would cause ppm2tiff to crash or, possibly, execute arbitrary code.
(CVE-2012-4564)

All running applications linked against libtiff must be restarted for this update to take effect.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?8043693b

Plugin Details

Severity: Medium

ID: 63314

File Name: sl_20121218_libtiff_on_SL5_x.nasl

Version: 1.8

Type: local

Agent: unix

Published: 12/20/2012

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:fermilab:scientific_linux:libtiff, p-cpe:/a:fermilab:scientific_linux:libtiff-debuginfo, p-cpe:/a:fermilab:scientific_linux:libtiff-devel, p-cpe:/a:fermilab:scientific_linux:libtiff-static, x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 12/18/2012

Vulnerability Publication Date: 8/13/2012

Reference Information

CVE: CVE-2012-3401, CVE-2012-4447, CVE-2012-4564, CVE-2012-5581