Executive Summary
Summary | |
---|---|
Title | New TIFF packages fix arbitrary code execution |
Informations | |||
---|---|---|---|
Name | DSA-1091 | First vendor Publication | 2006-06-08 |
Vendor | Debian | Last vendor Modification | 2006-06-08 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Several problems have been discovered in the TIFF library. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2006-2193 SuSE discovered a buffer overflow in the conversion of TIFF files into PDF documents which could be exploited when tiff2pdf is used e.g. in a printer filter. CVE-2006-2656 The tiffsplit command from the TIFF library contains a buffer overflow in the commandline handling which could be exploited when the program is executed automatically on unknown filenames. For the old stable distribution (woody) this problem has been fixed in version 3.5.5-7woody2. For the stable distribution (sarge) this problem has been fixed in version 3.7.2-5. For the unstable distribution (sid) this problem has been fixed in version 3.8.2-4. We recommend that you upgrade your tiff packages. |
Original Source
Url : http://www.debian.org/security/2006/dsa-1091 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:9788 | |||
Oval ID: | oval:org.mitre.oval:def:9788 | ||
Title: | Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call. | ||
Description: | Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2006-2193 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-03-06 | Name : RedHat Update for libtiff RHSA-2008:0848-01 File : nvt/gb_RHSA-2008_0848-01_libtiff.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200607-03 (tiff) File : nvt/glsa_200607_03.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1091-1 (tiff) File : nvt/deb_1091_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
26031 | LibTIFF tiff2pdf t2p_write_pdf_string Function Overflow |
26030 | LibTIFF tiffsplit Filename Processing Overflow |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2006-0603.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2008-0848.nasl - Type : ACT_GATHER_INFO |
2013-06-29 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2008-0848.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20080828_libtiff_on_SL3_x.nasl - Type : ACT_GATHER_INFO |
2008-08-30 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2008-0848.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-289-1.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_tiff-1594.nasl - Type : ACT_GATHER_INFO |
2007-01-17 | Name : The remote Fedora Core host is missing a security update. File : fedora_2006-591.nasl - Type : ACT_GATHER_INFO |
2007-01-17 | Name : The remote Fedora Core host is missing a security update. File : fedora_2006-952.nasl - Type : ACT_GATHER_INFO |
2006-10-14 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1091.nasl - Type : ACT_GATHER_INFO |
2006-08-07 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2006-0603.nasl - Type : ACT_GATHER_INFO |
2006-08-04 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2006-0603.nasl - Type : ACT_GATHER_INFO |
2006-07-10 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200607-03.nasl - Type : ACT_GATHER_INFO |
2006-06-16 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2006-102.nasl - Type : ACT_GATHER_INFO |
2006-06-06 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2006-095.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:25:53 |
|