Package name
libtiff
Date
2012-04-05
Advisory ID
MDVSA-2012:054
Affected versions
MES5 i586 , 2010.1 i586 , 2011 x86_64 , 2011 i586 , MES5 x86_64 , 2010.1 x86_64

Problem description

A vulnerability has been found and corrected in libtiff:

An integer overflow was discovered in the libtiff/tiff_getimage.c
file in the tiff library which could cause execution of arbitrary
code using a specially crafted TIFF image file (CVE-2012-1173).

The updated packages have been patched to correct this issue.

Updated packages

MES5 i586

 9fb8e22275d5bcaf53d14b00eeca7aa7  mes5/i586/libtiff3-3.8.2-12.6mdvmes5.2.i586.rpm
 850f81758fec478e140cf070957a4375  mes5/i586/libtiff3-devel-3.8.2-12.6mdvmes5.2.i586.rpm
 46a57be63439335b13195b5c42ffba08  mes5/i586/libtiff3-static-devel-3.8.2-12.6mdvmes5.2.i586.rpm
 7bc897d253fb5afa777f53dd424d3455  mes5/i586/libtiff-progs-3.8.2-12.6mdvmes5.2.i586.rpm 
 00c25dda398dda7dba18992da2fc2ccd  mes5/SRPMS/libtiff-3.8.2-12.6mdvmes5.2.src.rpm

2010.1 i586

 30b78030f2f8e07a36427fef8ec0db89  2010.1/i586/libtiff3-3.9.2-2.6mdv2010.2.i586.rpm
 345b426d43cdf89a5cbb30d6cb5bf32c  2010.1/i586/libtiff-devel-3.9.2-2.6mdv2010.2.i586.rpm
 0285a9b99bc35899603aff4f98581cc1  2010.1/i586/libtiff-progs-3.9.2-2.6mdv2010.2.i586.rpm
 aa65357089997f0d547f3c7ea49d4a70  2010.1/i586/libtiff-static-devel-3.9.2-2.6mdv2010.2.i586.rpm 
 9c1b1e298e3d45789ee53718a987e96d  2010.1/SRPMS/libtiff-3.9.2-2.6mdv2010.2.src.rpm

2011 x86_64

 97e5386e294a4e430ac981f469886e7f  2011/x86_64/lib64tiff3-3.9.5-1.1-mdv2011.0.x86_64.rpm
 c2abd760b3478eee4984b58b0a158172  2011/x86_64/lib64tiff-devel-3.9.5-1.1-mdv2011.0.x86_64.rpm
 0a4b52ccde8f52932a89aa3f6273d592  2011/x86_64/lib64tiff-static-devel-3.9.5-1.1-mdv2011.0.x86_64.rpm
 f7113aa5d0b90dfa9c4a5893f69bd608  2011/x86_64/libtiff-progs-3.9.5-1.1-mdv2011.0.x86_64.rpm 
 cee2ab101a8807bbff58d006c6377403  2011/SRPMS/libtiff-3.9.5-1.1.src.rpm

2011 i586

 6a6e55530472e86f78466485254d2b66  2011/i586/libtiff3-3.9.5-1.1-mdv2011.0.i586.rpm
 3e63f1bad83a94f27ec2e497b2448127  2011/i586/libtiff-devel-3.9.5-1.1-mdv2011.0.i586.rpm
 feea28562b47942805bdf5c199fcb8e3  2011/i586/libtiff-progs-3.9.5-1.1-mdv2011.0.i586.rpm
 ba8a44b4031e45d20ee577f68169646a  2011/i586/libtiff-static-devel-3.9.5-1.1-mdv2011.0.i586.rpm 
 cee2ab101a8807bbff58d006c6377403  2011/SRPMS/libtiff-3.9.5-1.1.src.rpm

MES5 x86_64

 20e5a4a575d4f56d8517bb25b7d06215  mes5/x86_64/lib64tiff3-3.8.2-12.6mdvmes5.2.x86_64.rpm
 447dad3a97edd653c9e6afc5156d0b1b  mes5/x86_64/lib64tiff3-devel-3.8.2-12.6mdvmes5.2.x86_64.rpm
 7dfa313d7546f8da736ec0e3029ac4a6  mes5/x86_64/lib64tiff3-static-devel-3.8.2-12.6mdvmes5.2.x86_64.rpm
 8be2e5500223561f7bccd560c627be1b  mes5/x86_64/libtiff-progs-3.8.2-12.6mdvmes5.2.x86_64.rpm 
 00c25dda398dda7dba18992da2fc2ccd  mes5/SRPMS/libtiff-3.8.2-12.6mdvmes5.2.src.rpm

2010.1 x86_64

 7278bcf02dcdfc44a27cf424b39e22de  2010.1/x86_64/lib64tiff3-3.9.2-2.6mdv2010.2.x86_64.rpm
 8336e8c6807dfeb01786bb0120979b5d  2010.1/x86_64/lib64tiff-devel-3.9.2-2.6mdv2010.2.x86_64.rpm
 9e32cc90de20e28d51ce34039c6c6437  2010.1/x86_64/lib64tiff-static-devel-3.9.2-2.6mdv2010.2.x86_64.rpm
 3bde6e68069c0f519017bca6176c5809  2010.1/x86_64/libtiff-progs-3.9.2-2.6mdv2010.2.x86_64.rpm 
 9c1b1e298e3d45789ee53718a987e96d  2010.1/SRPMS/libtiff-3.9.2-2.6mdv2010.2.src.rpm

References