Ubuntu Security Notice USN-277-1
3rd May, 2006
tiff vulnerabilities
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 5.10
- Ubuntu 5.04
Details
Tavis Ormandy and Andrey Kiselev discovered that libtiff did not
sufficiently verify the validity of TIFF files. By tricking an user
into opening a specially crafted TIFF file with any application that
uses libtiff, an attacker could exploit this to crash the application
or even execute arbitrary code with the application's privileges.
Update instructions
The problem can be corrected by updating your system to the following package version:
- Ubuntu 5.10:
- libtiff4
- Ubuntu 5.04:
- libtiff4
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
None