
USN-3212-4: LibTIFF vulnerabilities
USN-3212-4: LibTIFF vulnerabilities Ubuntu Security Notice USN-3212-4 7th August, 2017 tiff vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file. Software description tiff – Tag Image File Format (TIFF) library Details USN-3212-1 fixed several issues in LibTIFF. This updateprovides a subset of corresponding update for Ubuntu 12.04 ESM. Mei Wang discovered a multiple integer overflows in LibTIFF whichallows remote attackers to cause a denial of service (crash) orexecute arbitrary code via a crafted TIFF image, which triggersan out-of-bounds write. (CVE-2016-3945) It was discovered that LibTIFF is vulnerable to a heap bufferoverflow in the resulting in DoS or code executionvia a crafted BitsPerSample value. (CVE-2017-5225) Original advisory details: It was discovered that LibTIFF incorrectly handled [ more… ]