Lucene search

K
osvGoogleOSV:DSA-1091-1
HistoryJun 08, 2006 - 12:00 a.m.

tiff - buffer overflows

2006-06-0800:00:00
Google
osv.dev
9

0.029 Low

EPSS

Percentile

90.9%

Several problems have been discovered in the TIFF library. The Common
Vulnerabilities and Exposures project identifies the following issues:

  • CVE-2006-2193
    SuSE discovered a buffer overflow in the conversion of TIFF files
    into PDF documents which could be exploited when tiff2pdf is used
    e.g. in a printer filter.
  • CVE-2006-2656
    The tiffsplit command from the TIFF library contains a buffer
    overflow in the commandline handling which could be exploited when
    the program is executed automatically on unknown filenames.

For the old stable distribution (woody) this problem has been fixed in
version 3.5.5-7woody2.

For the stable distribution (sarge) this problem has been fixed in
version 3.7.2-5.

For the unstable distribution (sid) this problem has been fixed in
version 3.8.2-4.

We recommend that you upgrade your tiff packages.

CPENameOperatorVersion
tiffeq3.7.2-3
tiffeq3.7.2-3sarge1
tiffeq3.7.2-4