LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
BID:19283
CVE-2006-3459 |Info
LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 19283 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3459 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2006 12:00AM |
| Updated: | Aug 25 2008 07:35PM |
| Credit: | Tavis Ormandy of Google Security Team is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 SuSE SUSE Linux Enterprise SDK 10 SuSE Linux Enterprise Server 9 SuSE Linux Enterprise Server 10 SuSE Linux Desktop 1.0 Sun Trusted Solaris 8.0 x86 Sun Trusted Solaris 8.0 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10.0_x86 Sun Solaris 10.0 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 SGI ProPack 3.0 SP6 S.u.S.E. UnitedLinux 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 rPath rPath Linux 1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 LibTIFF LibTIFF 3.8.2 LibTIFF LibTIFF 3.8.1 LibTIFF LibTIFF 3.8 LibTIFF LibTIFF 3.7.3 LibTIFF LibTIFF 3.7.2 LibTIFF LibTIFF 3.7.1 LibTIFF LibTIFF 3.7 LibTIFF LibTIFF 3.6.1 LibTIFF LibTIFF 3.6 .0 LibTIFF LibTIFF 3.5.7 LibTIFF LibTIFF 3.5.5 LibTIFF LibTIFF 3.5.4 LibTIFF LibTIFF 3.5.3 LibTIFF LibTIFF 3.5.2 LibTIFF LibTIFF 3.5.1 LibTIFF LibTIFF 3.4 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Cosmicperl Directory Pro 10.0.3 Avaya Messaging Storage Server Avaya Message Networking Avaya Intuity LX Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.3.9 Apple Mac OS X Server 10.3.8 Apple Mac OS X Server 10.3.7 Apple Mac OS X Server 10.3.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X Server 10.2.8 Apple Mac OS X Server 10.2.7 Apple Mac OS X Server 10.2.6 Apple Mac OS X Server 10.2.5 Apple Mac OS X Server 10.2.4 Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Mac OS X Server 10.1.5 Apple Mac OS X Server 10.1.4 Apple Mac OS X Server 10.1.3 Apple Mac OS X Server 10.1.2 Apple Mac OS X Server 10.1.1 Apple Mac OS X Server 10.1 Apple Mac OS X Server 10.0 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 Apple Mac OS X 10.2.8 Apple Mac OS X 10.2.7 Apple Mac OS X 10.2.6 Apple Mac OS X 10.2.5 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 Apple Mac OS X 10.1.5 Apple Mac OS X 10.1.4 Apple Mac OS X 10.1.3 Apple Mac OS X 10.1.2 Apple Mac OS X 10.1.1 Apple Mac OS X 10.1 Apple Mac OS X 10.1 Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 3 Apple Mac OS X 10.0 Apple iPod Touch 1.1.1 Apple iPod Touch 1.1 Apple iPhone 1.1.1 Apple iPhone 1.0.2 Apple iPhone 1.0.1 Apple iPhone 1 |
| Not Vulnerable: | |
Discussion
LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
LibTIFF is prone to a buffer-overflow vulnerability because the library fails to do proper boundary checks before copying user-supplied data into a finite-sized buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of appications using the affected library. Failed exploit attempts will likely crash the application, denying service to legitimate users.
LibTIFF is prone to a buffer-overflow vulnerability because the library fails to do proper boundary checks before copying user-supplied data into a finite-sized buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of appications using the affected library. Failed exploit attempts will likely crash the application, denying service to legitimate users.
Exploit / POC
LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
Solution:
Please see the referenced advisories for information on obtaining and applying fixes.
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.3.9
Apple Mac OS X 10.4.7
LibTIFF LibTIFF 3.7.3
Solution:
Please see the referenced advisories for information on obtaining and applying fixes.
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2006-004Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=11231&cat= 1&platform=osx&method=sa/SecUpdSrvr2006-004Pan.dmg
Apple Mac OS X 10.3.9
-
Apple SecUpd2006-004Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=11230&cat= 1&platform=osx&method=sa/SecUpd2006-004Pan.dmg
Apple Mac OS X 10.4.7
-
Apple SecUpd2006-004Intel.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=11232&cat= 1&platform=osx&method=sa/SecUpd2006-004Intel.dmg
LibTIFF LibTIFF 3.7.3
-
Trustix libtiff-3.7.3-4tr.i586.rpm
Trustix Secure Linux 3.0
ftp://ftp.trustix.org/pub/trustix/updates -
Trustix libtiff-devel-3.7.3-4tr.i586.rpm
Trustix Secure Linux 3.0
ftp://ftp.trustix.org/pub/trustix/updates -
Trustix libtiff-docs-3.7.3-4tr.i586.rpm
Trustix Secure Linux 3.0
ftp://ftp.trustix.org/pub/trustix/updates -
Ubuntu libtiff-opengl_3.7.3-1ubuntu1.5_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_ 3.7.3-1ubuntu1.5_amd64.deb -
Ubuntu libtiff-opengl_3.7.3-1ubuntu1.5_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_ 3.7.3-1ubuntu1.5_i386.deb -
Ubuntu libtiff-opengl_3.7.3-1ubuntu1.5_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_ 3.7.3-1ubuntu1.5_powerpc.deb -
Ubuntu libtiff-opengl_3.7.3-1ubuntu1.5_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_ 3.7.3-1ubuntu1.5_sparc.deb -
Ubuntu libtiff-tools_3.7.3-1ubuntu1.5_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.7.3 -1ubuntu1.5_amd64.deb -
Ubuntu libtiff-tools_3.7.3-1ubuntu1.5_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.7.3 -1ubuntu1.5_i386.deb -
Ubuntu libtiff-tools_3.7.3-1ubuntu1.5_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.7.3 -1ubuntu1.5_powerpc.deb -
Ubuntu libtiff-tools_3.7.3-1ubuntu1.5_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.7.3 -1ubuntu1.5_sparc.deb -
Ubuntu libtiff4-dev_3.7.3-1ubuntu1.5_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.7.3- 1ubuntu1.5_amd64.deb -
Ubuntu libtiff4-dev_3.7.3-1ubuntu1.5_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.7.3- 1ubuntu1.5_i386.deb -
Ubuntu libtiff4-dev_3.7.3-1ubuntu1.5_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.7.3- 1ubuntu1.5_powerpc.deb -
Ubuntu libtiff4-dev_3.7.3-1ubuntu1.5_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.7.3- 1ubuntu1.5_sparc.deb -
Ubuntu libtiff4_3.7.3-1ubuntu1.5_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.7.3-1ubu ntu1.5_amd64.deb -
Ubuntu libtiff4_3.7.3-1ubuntu1.5_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.7.3-1ubu ntu1.5_i386.deb -
Ubuntu libtiff4_3.7.3-1ubuntu1.5_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.7.3-1ubu ntu1.5_powerpc.deb -
Ubuntu libtiff4_3.7.3-1ubuntu1.5_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.7.3-1ubu ntu1.5_sparc.deb -
Ubuntu libtiffxx0c2_3.7.3-1ubuntu1.5_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.7.3- 1ubuntu1.5_amd64.deb -
Ubuntu libtiffxx0c2_3.7.3-1ubuntu1.5_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.7.3- 1ubuntu1.5_i386.deb -
Ubuntu libtiffxx0c2_3.7.3-1ubuntu1.5_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.7.3- 1ubuntu1.5_powerpc.deb -
Ubuntu libtiffxx0c2_3.7.3-1ubuntu1.5_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.7.3- 1ubuntu1.5_sparc.deb
References
LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
References:
References:
- ASA-2006-166 - libtiff security update (RHSA-2006-0603) (Avaya)
- LibTIFF Homepage (LibTIFF)
- RHSA-2006:0603-4 - libtiff security update (Red Hat)
- RHSA-2006:0648-4 - kdegraphics security update (Red Hat)
- Sun Advisory 201331 - Security Vulnerabilities in libtiff(3) May Allow Denial of (Sun)
- Cracking the iPhone (5 article series) (H D Moore
) - rPSA-2006-0142-1 libtiff (rPath)