Package name
libtiff
Date
2013-08-06
Advisory ID
MDVSA-2013:208
Affected versions
MBS1 x86_64

Problem description

Updated libtiff packages fix security vulnerabilities:

A heap-based buffer overflow flaw was found in the way tiff2pdf of
libtiff performed write of TIFF image content into particular PDF
document file, in the tp_process_jpeg_strip() function. A remote
attacker could provide a specially-crafted TIFF image format file,
that when processed by tiff2pdf would lead to tiff2pdf executable
crash or, potentially, arbitrary code execution with the privileges
of the user running the tiff2pdf binary (CVE-2013-1960).

A stack-based buffer overflow was found in the way tiff2pdf of libtiff
performed write of TIFF image content into particular PDF document
file, when malformed image-length and resolution values are used in
the TIFF file. A remote attacker could provide a specially-crafted
TIFF image format file, that when processed by tiff2pdf would lead
to tiff2pdf executable crash (CVE-2013-1961).

Updated packages

MBS1 x86_64

 a220e740d95cecb9ba75e7cc7da597e1  mbs1/x86_64/lib64tiff5-4.0.1-3.2.mbs1.x86_64.rpm
 14f548564a07eb9b4f227dc7892b968d  mbs1/x86_64/lib64tiff-devel-4.0.1-3.2.mbs1.x86_64.rpm
 e41641f5e59c3cce2b83be367ed16512  mbs1/x86_64/lib64tiff-static-devel-4.0.1-3.2.mbs1.x86_64.rpm
 a096aca7f52ec8a391aeda5e113e2adf  mbs1/x86_64/libtiff-progs-4.0.1-3.2.mbs1.x86_64.rpm 
 62ecd6b8fd59cd5fa3842b2fc5dab7da  mbs1/SRPMS/libtiff-4.0.1-3.2.mbs1.src.rpm

References