Debian Security Advisory
DSA-2256-1 tiff -- buffer overflow
- Date Reported:
- 09 Jun 2011
- Affected Packages:
- tiff
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 624287.
In Mitre's CVE dictionary: CVE-2009-5022. - More information:
-
Tavis Ormandy discovered that the Tag Image File Format (TIFF) library is vulnerable to a buffer overflow triggered by a crafted OJPEG file which allows for a crash and potentially execution of arbitrary code.
The oldstable distribution (lenny) is not affected by this problem.
For the stable distribution (squeeze), this problem has been fixed in version 3.9.4-5+squeeze2.
For the testing distribution (wheezy) and unstable distribution (sid), this problem has been fixed in version 3.9.5-1.
We recommend that you upgrade your tiff packages.