OracleVM 2.1 : libtiff (OVMSA-2009-0027)

high Nessus Plugin ID 79467

Synopsis

The remote OracleVM host is missing one or more security updates.

Description

The remote OracleVM system is missing necessary patches to address critical security updates :

- Fix buffer overrun risks caused by unchecked integer overflow (CVE-2009-2347) Resolves: #507725

- Fix some more LZW decoding vulnerabilities (CVE-2009-2285) Resolves: #507725

- Update upstream URL

- Use -fno-strict-aliasing per rpmdiff recommendation

- Fix LZW decoding vulnerabilities (CVE-2008-2327) Resolves: #458812

- Remove sgi2tiff.1 and tiffsv.1, since they are for programs we don't ship Resolves: #460120

Solution

Update the affected libtiff / libtiff-devel packages.

See Also

http://www.nessus.org/u?2af78c77

Plugin Details

Severity: High

ID: 79467

File Name: oraclevm_OVMSA-2009-0027.nasl

Version: 1.11

Type: local

Published: 11/26/2014

Updated: 1/14/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:libtiff, p-cpe:/a:oracle:vm:libtiff-devel, cpe:/o:oracle:vm_server:2.1

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/19/2009

Vulnerability Publication Date: 8/27/2008

Reference Information

CVE: CVE-2008-2327, CVE-2009-2285, CVE-2009-2347

BID: 30832, 35451, 35652

CWE: 119, 189