Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

LibTIFF Multiple Buffer Overflow Vulnerabilities

Solution:
SGI has released an advisory 20050404-01-U including updated SGI ProPack 3 Service Pack 5 packages to address these and other issues. Please see the referenced advisory for more information.

Red Hat has released advisory RHSA-2005:021-09 and fixes to address this issue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see the referenced advisory for additional information.

SCO has released an advisory (SCOSA-2005.19) and fixes to address these issues for UnixWare platforms. Please see the referenced advisory for further information.

SGI has released an advisory 20050401-01-U including updated SGI ProPack 3 Service Pack 4 packages to address this issue. Please see the referenced advisory for more information.

Mandrake has released an advisory (MDKSA-2004:111) to address these issues in wxGTK2, which is derived from the libtiff source. Customers are advised to see the referenced advisory for further information in regards to obtaining and applying appropriate fixes.

Gentoo Linux has released advisory GLSA 200410-11 dealing with this issue. All TIFF library users are advised to update their packages with the following commands:

# emerge sync

# emerge -pv ">=media-libs/tiff-3.6.1-r2"
# emerge ">=media-libs/tiff-3.6.1-r2"

Furthermore Gentoo advises that all xv users update their packages with the following commands:

# emerge sync

# emerge -pv ">=media-gfx/xv-3.10a-r8"
# emerge ">=media-gfx/xv-3.10a-r8"

For more information please see the referenced Gentoo Linux advisory.

OpenPKG has released advisory OpenPKG-SA-2004.043 along with fixes dealing with this issue. Please see the referenced advisory for more information.

RedHat Fedora has released an advisory (FEDORA-2004-334) along with fixes for their Core 2 product. Please see the referenced advisory for more information.

Trustix Secure Linux has released advisory TSLSA-2004-0054 along with fixes to address this issue. Please see the referenced advisory for further information.

Debian has released an advisory (DSA 567-1) along with fixes dealing with this issue. Please see the referenced advisory for more information.

MandrakeSoft has issued patches for Mandrake Linux.

SuSE Linux has released advisory SUSE-SA:2004:038 along with fixes to address these issues. Please see the referenced advisory for further information.

RedHat has released advisory RHSA-2004:577-16 to address these issues in RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information.

RedHat has released advisory FEDORA-2004-357 along with fixes to address these issues in RedHat Fedora Core 2. Please see the referenced advisory for further information.

Slackware Linux has released advisory SSA:2004-305-02 along with fixes dealing with this issue. Please see the referenced advisory for more information.

Conectiva has released an advisory (CLA-2004:888) to address these issues. Please see the referenced advisory for more information.

Apple has released an advisory (APPLE-SA-2004-12-02) dealing with this and other issues. Please see the referenced advisory for more information.

Gentoo linux has released advisory GLSA 200412-02 dealing with this issue for their PDFLib packages. All PDFlib users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/pdflib-5.0.4_p1"

For more information, please see the referenced Gentoo Linux advisory for more information.

KDE has released an advisory dealing with this issue. Apparently this issue affects KDE because an application included in its distribution contains a copy of the vulnerable library. This issue has been resolved in KDE's latest release (version 3.3.2). Please see the referenced advisory.

Avaya has released advisory ASA-2005-002 stating which Avaya products are affected by these vulnerabilities. Please see the referenced advisory for further information.

Conectiva has released an advisory CLA-2005:914 to address these issues in wxGTK. Please see the referenced advisory for more information.

TurboLinux has released a security announcement and fixes to address this and other vulnerabilities. Please see the referenced announcement for further information regarding obtaining and applying appropriate updates.

Mandrake has released advisory MDKSA-2005:052 to address various issues affecting kdegraphics. Please see the referenced advisory for more information.

Red Hat has released advisory RHSA-2005:354-03 and fixes to address this issue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.

Sun has released fixes for Solaris 7, 8, and 9. Additional fixes are pending.

Sun has updated Sun Alert ID 101677 (formerly 57769), and provided a fix for Solaris 10 x86 (patch 119901-01). Further fixes are still pending. Please see the referenced advisory for further information.

Sun has updated Sun Alert ID 101677 (formerly 57769), and provided a fix for Solaris 10 SPARC (patch 119900-01). Further fixes are still pending. Please see the referenced advisory for further information.


Sun Solaris 8

Sun Solaris 10

Sun Solaris 10.0_x86

Sun Solaris 7.0

Sun Solaris 9

Sun Solaris 9_x86 Update 2

Apple Mac OS X 10.2

Apple Mac OS X 10.2.1

Apple Mac OS X 10.2.2

Apple Mac OS X 10.2.3

Apple Mac OS X 10.2.4

Apple Mac OS X 10.2.5

Apple Mac OS X 10.2.7

Apple Mac OS X 10.2.8

Apple Mac OS X Server 10.2.8

Apple Mac OS X 10.3

Apple Mac OS X 10.3.1

Apple Mac OS X 10.3.2

Apple Mac OS X 10.3.3

Apple Mac OS X 10.3.4

Apple Mac OS X 10.3.5

Apple Mac OS X Server 10.3.6

wxGTK2 wxGTK2 2.5 .0

KDE KDE 3.2

KDE KDE 3.2.3

LibTIFF LibTIFF 3.5.5

LibTIFF LibTIFF 3.6 .0

LibTIFF LibTIFF 3.6.1

SCO Unixware 7.1.4







 

Privacy Statement
Copyright 2008, SecurityFocus