Debian Security Advisory
DSA-2552-1 tiff -- several vulnerabilities
- Date Reported:
- 26 Sep 2012
- Affected Packages:
- Security database references:
- In the Debian bugtracking system: Bug 678140.
In Mitre's CVE dictionary: CVE-2010-2482, CVE-2010-2595, CVE-2010-2597, CVE-2010-2630, CVE-2010-4665, CVE-2012-2088, CVE-2012-2113, CVE-2012-3401.
- More information:
Several vulnerabilities were discovered in TIFF, a library set and tools to support the Tag Image File Format (TIFF), allowing denial of service and potential privilege escalation.
These vulnerabilities can be exploited via a specially crafted TIFF image.
The tiff2pdf utility has an integer overflow error when parsing images.
Huzaifa Sidhpurwala discovered heap-based buffer overflow in the t2p_read_tiff_init() function.
An invalid td_stripbytecount field is not properly handle and can trigger a NULL pointer dereference.
An array index error, related to
downsampled OJPEG inputin the TIFFYCbCrtoRGB function causes an unexpected crash.
Also related to
downsampled OJPEG input, the TIFFVStripSize function crash unexpectly.
The TIFFReadDirectory function does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file.
The tiffdump utility has an integer overflow in the ReadDirectory function.
For the stable distribution (squeeze), these problems have been fixed in version 3.9.4-5+squeeze5.
For the testing distribution (wheezy), these problems have been fixed in version 4.0.2-2.
For the unstable distribution (sid), these problems have been fixed in version 4.0.2-2.
We recommend that you upgrade your tiff packages.