Lucene search

K
redhatRedHatRHSA-2011:0318
HistoryMar 02, 2011 - 12:00 a.m.

(RHSA-2011:0318) Important: libtiff security update

2011-03-0200:00:00
access.redhat.com
17

0.048 Low

EPSS

Percentile

92.7%

The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

A heap-based buffer overflow flaw was found in the way libtiff processed
certain TIFF Internet Fax image files, compressed with the CCITT Group 4
compression algorithm. An attacker could use this flaw to create a
specially-crafted TIFF file that, when opened, would cause an application
linked against libtiff to crash or, possibly, execute arbitrary code.
(CVE-2011-0192)

Red Hat would like to thank Apple Product Security for reporting this
issue.

All libtiff users should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running applications linked
against libtiff must be restarted for this update to take effect.