Wednesday, September 11, 2024

[USN-6997-2] LibTIFF vulnerability

-----BEGIN PGP SIGNATURE-----

wsD5BAABCAAjFiEEcxdv4gCCE8W9nrt5a1+PL+d1/EgFAmbh5lIFAwAAAAAACgkQa1+PL+d1/Ejr
7Av/c3V9ZlAUaU/n82QFIfzcBRB/dpZGLbI3CsWFocmyTaQ2HF36oS+NimfGA5GPzTyHQ03hZUyd
TbHS9VaXQ/JieLnyl4UJk/xa7sdNsQYm5M7bbgEMkfE5LrA21zHFqcezjyRpE1dwgh+PxzDzRt+9
DrnbuNHkob5MP2eRZqhOO7CPLHtTZZCOkC3ewABlZmGEa3Tg/UkNmUcF//G8Iw4cKicTUzwf8tF1
IVXPn8uY6c1EFqI9bSKSgwjd4ZKxEs/axzeG9BSju9VhcV7CtIKwRNb92PFrMgRNYuWg3sN8LoEB
ivSAflHqqhsgXOQw55BCAPcNJNZSy7gn6aLScih0DfQEg0jiAEZxqgzN0zi3eCZMH//JbGtK97U4
pkIk8abYjoohjd430G5E5dIJ3KfoU1GcyPzt0LKL6MoEQeMYVxP2NeuGlEY/L7qiJT286aKjP8vf
GeO4f2RNjmuIBHiq28+o3HQ48fRQWcrhf6T0IrOX8xKWJaAOjCysSiRzchDV
=tR3B
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6997-2
September 11, 2024

tiff vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

LibTIFF could be made to crash if it received specially crafted input.

Software Description:
- tiff: Tag Image File Format (TIFF) library

Details:

USN-6997-1 fixed a vulnerability in LibTIFF. This update
provides the corresponding updates for Ubuntu 14.04 LTS.

Original advisory details:

 It was discovered that LibTIFF incorrectly handled memory. An attacker
 could possibly use this issue to cause the application to crash, resulting
 in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS
  libtiff-opengl                  4.0.3-7ubuntu0.11+esm14
                                  Available with Ubuntu Pro
  libtiff-tools                   4.0.3-7ubuntu0.11+esm14
                                  Available with Ubuntu Pro
  libtiff5                        4.0.3-7ubuntu0.11+esm14
                                  Available with Ubuntu Pro
  libtiffxx5                      4.0.3-7ubuntu0.11+esm14
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-6997-2
  https://ubuntu.com/security/notices/USN-6997-1
  CVE-2024-7006

No comments:

Post a Comment