LibTIFF Next RLE Decoder Remote Heap Buffer Overflow Vulnerability
BID:19282
CVE-2006-3462 |Info
LibTIFF Next RLE Decoder Remote Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 19282 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3462 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2006 12:00AM |
| Updated: | Aug 25 2008 07:25PM |
| Credit: | Tavis Ormandy is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 SuSE SUSE Linux Enterprise Server 8 SuSE Linux Desktop 1.0 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun Solaris 10 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 SGI ProPack 3.0 SP6 S.u.S.E. UnitedLinux 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 10.1 rPath rPath Linux 1 Redhat Fedora Core5 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 LibTIFF LibTIFF 3.8.2 LibTIFF LibTIFF 3.8.1 LibTIFF LibTIFF 3.8 LibTIFF LibTIFF 3.7.3 LibTIFF LibTIFF 3.7.2 LibTIFF LibTIFF 3.7.1 LibTIFF LibTIFF 3.7 LibTIFF LibTIFF 3.6.1 LibTIFF LibTIFF 3.6 .0 LibTIFF LibTIFF 3.5.7 LibTIFF LibTIFF 3.5.5 LibTIFF LibTIFF 3.5.4 LibTIFF LibTIFF 3.5.3 LibTIFF LibTIFF 3.5.2 LibTIFF LibTIFF 3.5.1 LibTIFF LibTIFF 3.4 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Cosmicperl Directory Pro 10.0.3 Avaya Messaging Storage Server Avaya Message Networking Avaya Intuity LX Apple Mac OS X 10.3.9 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 Apple Mac OS X 10.2.8 Apple Mac OS X 10.2.7 Apple Mac OS X 10.2.6 Apple Mac OS X 10.2.5 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 Apple Mac OS X 10.1.5 Apple Mac OS X 10.1.4 Apple Mac OS X 10.1.3 Apple Mac OS X 10.1.2 Apple Mac OS X 10.1.1 Apple Mac OS X 10.1 Apple Mac OS X 10.1 Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 3 Apple Mac OS X 10.0 Apple Mac OS 9 9.2.2 Apple Mac OS 9 9.2.1 Apple Mac OS 9 9.2 Apple Mac OS 9 9.1 Apple Mac OS 9 9.0.4 Apple Mac OS 9 9.0 Apple Mac OS 8 8.6 Apple Mac OS 8 8.5 Apple Mac OS 8 8.1 Apple Mac OS 8 8.0 Apple Mac OS 7 7.6.1 Apple Mac OS 7 7.6 Apple Mac OS 7 7.5.3 Apple Mac OS 7 7.5.2 Apple Mac OS 7 7.5.1 Apple Mac OS 7 7.1.2 Apple Mac OS 7 7.1 Apple Mac OS 7 7.0.1 Apple Mac OS 7 7.0 Apple Mac OS 6 6.0.8 Apple iPod Touch 1.1.1 Apple iPod Touch 1.1 Apple iPhone 1.1.1 Apple iPhone 1.0.2 Apple iPhone 1.0.1 Apple iPhone 1 |
| Not Vulnerable: | |
Discussion
LibTIFF Next RLE Decoder Remote Heap Buffer Overflow Vulnerability
The Next RLE Decoder for libTIFF is prone to a remote heap buffer-overflow vulnerability.
This issue occurs because the application fails to check boundary conditions on certain RLE decoding operations.
This issue may allow attackers to execute arbitrary machine code within the context of the vulnerable application or to cause a denial of service.
The Next RLE Decoder for libTIFF is prone to a remote heap buffer-overflow vulnerability.
This issue occurs because the application fails to check boundary conditions on certain RLE decoding operations.
This issue may allow attackers to execute arbitrary machine code within the context of the vulnerable application or to cause a denial of service.
Exploit / POC
LibTIFF Next RLE Decoder Remote Heap Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. if you feel we are error or if you are aware of more recent information, please email us at [email protected]
Currently we are not aware of any exploits for this issue. if you feel we are error or if you are aware of more recent information, please email us at [email protected]
Solution / Fix
LibTIFF Next RLE Decoder Remote Heap Buffer Overflow Vulnerability
Solution:
Please see the referenced advisories for information on obtaining and applying the appropriate updates.
Sun Solaris 10
Apple Mac OS X 10.3.9
LibTIFF LibTIFF 3.5.7
LibTIFF LibTIFF 3.7.3
Solution:
Please see the referenced advisories for information on obtaining and applying the appropriate updates.
Sun Solaris 10
-
Sun Solaris 10 SPARC patch 119900-03
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -119900-03-1
Apple Mac OS X 10.3.9
-
Apple SecUpd2006-004Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=11230&cat= 1&platform=osx&method=sa/SecUpd2006-004Pan.dmg
LibTIFF LibTIFF 3.5.7
-
Slackware libtiff-3.8.2-i386-1_slack9.0.tgz
Slackware 9.0:
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/l ibtiff-3.8.2-i386-1_slack9.0.tgz -
Slackware libtiff-3.8.2-i486-1_slack9.1.tgz
Slackware 9.0:
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/l ibtiff-3.8.2-i486-1_slack9.1.tgz
LibTIFF LibTIFF 3.7.3
-
Trustix libtiff-3.7.3-4tr.i586.rpm
Trustix Secure Linux 3.0
ftp://ftp.trustix.org/pub/trustix/updates -
Trustix libtiff-devel-3.7.3-4tr.i586.rpm
Trustix Secure Linux 3.0
ftp://ftp.trustix.org/pub/trustix/updates -
Trustix libtiff-docs-3.7.3-4tr.i586.rpm
Trustix Secure Linux 3.0
ftp://ftp.trustix.org/pub/trustix/updates -
Ubuntu libtiff-opengl_3.7.3-1ubuntu1.5_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_ 3.7.3-1ubuntu1.5_amd64.deb -
Ubuntu libtiff-opengl_3.7.3-1ubuntu1.5_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_ 3.7.3-1ubuntu1.5_i386.deb -
Ubuntu libtiff-opengl_3.7.3-1ubuntu1.5_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_ 3.7.3-1ubuntu1.5_powerpc.deb -
Ubuntu libtiff-opengl_3.7.3-1ubuntu1.5_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_ 3.7.3-1ubuntu1.5_sparc.deb -
Ubuntu libtiff-tools_3.7.3-1ubuntu1.5_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.7.3 -1ubuntu1.5_amd64.deb -
Ubuntu libtiff-tools_3.7.3-1ubuntu1.5_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.7.3 -1ubuntu1.5_i386.deb -
Ubuntu libtiff-tools_3.7.3-1ubuntu1.5_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.7.3 -1ubuntu1.5_powerpc.deb -
Ubuntu libtiff-tools_3.7.3-1ubuntu1.5_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.7.3 -1ubuntu1.5_sparc.deb -
Ubuntu libtiff4-dev_3.7.3-1ubuntu1.5_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.7.3- 1ubuntu1.5_amd64.deb -
Ubuntu libtiff4-dev_3.7.3-1ubuntu1.5_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.7.3- 1ubuntu1.5_i386.deb -
Ubuntu libtiff4-dev_3.7.3-1ubuntu1.5_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.7.3- 1ubuntu1.5_powerpc.deb -
Ubuntu libtiff4-dev_3.7.3-1ubuntu1.5_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.7.3- 1ubuntu1.5_sparc.deb -
Ubuntu libtiff4_3.7.3-1ubuntu1.5_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.7.3-1ubu ntu1.5_amd64.deb -
Ubuntu libtiff4_3.7.3-1ubuntu1.5_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.7.3-1ubu ntu1.5_i386.deb -
Ubuntu libtiff4_3.7.3-1ubuntu1.5_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.7.3-1ubu ntu1.5_powerpc.deb -
Ubuntu libtiff4_3.7.3-1ubuntu1.5_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.7.3-1ubu ntu1.5_sparc.deb -
Ubuntu libtiffxx0c2_3.7.3-1ubuntu1.5_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.7.3- 1ubuntu1.5_amd64.deb -
Ubuntu libtiffxx0c2_3.7.3-1ubuntu1.5_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.7.3- 1ubuntu1.5_i386.deb -
Ubuntu libtiffxx0c2_3.7.3-1ubuntu1.5_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.7.3- 1ubuntu1.5_powerpc.deb -
Ubuntu libtiffxx0c2_3.7.3-1ubuntu1.5_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.7.3- 1ubuntu1.5_sparc.deb
References
LibTIFF Next RLE Decoder Remote Heap Buffer Overflow Vulnerability
References:
References:
- ASA-2006-166 - libtiff security update (RHSA-2006-0603) (Avaya)
- RHSA-2006:0603-4 - libtiff security update (Red Hat)
- RHSA-2006:0648-4 - kdegraphics security update (Red Hat)
- Sun Advisory 201331 - Security Vulnerabilities in libtiff(3) May Allow Denial of (Sun)
- rPSA-2006-0142-1 libtiff (rPath)
- Multiple Security Vulnerabilities in the Solaris Tag Image File Format Library l (Sun Microsystems)