libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability
BID:46658
Info
libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability
| Bugtraq ID: | 46658 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-0192 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 02 2011 12:00AM |
| Updated: | May 07 2015 05:14PM |
| Credit: | Apple |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 ARM Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Symantec Clientless VPN Gateway 4400 Series 4.0 SP3 Symantec Clientless VPN Gateway 4400 Series 4.0 SP2 Symantec Clientless VPN Gateway 4400 Series 4.0 SP1 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise 11 SP1 SuSE SUSE Linux Enterprise 10 SP4 SuSE SUSE Linux Enterprise 10 SP3 SuSE openSUSE 11.4 SuSE openSUSE 11.3 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux x86_64 -current Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current S.u.S.E. openSUSE 11.2 Research In Motion Blackberry Enterprise Server for Novell Groupwise 5.0.1 MR3 Research In Motion Blackberry Enterprise Server for Novell Groupwise 5.0.1 Research In Motion Blackberry Enterprise Server for Novell Groupwise 5.0.0 Research In Motion Blackberry Enterprise Server for Novell Groupwise 4.1.7 Research In Motion Blackberry Enterprise Server for Novell Groupwise 4.1.4 Research In Motion Blackberry Enterprise Server for Novell Groupwise 4.1.3 Research In Motion Blackberry Enterprise Server for Novell Groupwise 4.1 Research In Motion Blackberry Enterprise Server for Novell Groupwise 4.0 SP3 Hotfix 1 Research In Motion Blackberry Enterprise Server for Exchange 4.0 SP1 Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 MR2 Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 Research In Motion Blackberry Enterprise Server for Exchange 5.0.2 MR1 Research In Motion Blackberry Enterprise Server for Exchange 5.0.2 Research In Motion Blackberry Enterprise Server for Exchange 5.0.1 Research In Motion Blackberry Enterprise Server for Exchange 5.0 SP2 Research In Motion Blackberry Enterprise Server for Exchange 5.0 Research In Motion Blackberry Enterprise Server for Exchange 4.1.7 Research In Motion Blackberry Enterprise Server for Exchange 4.1.4 Research In Motion Blackberry Enterprise Server for Exchange 4.1.3 Research In Motion Blackberry Enterprise Server for Exchange 4.1 Research In Motion Blackberry Enterprise Server for Exchange 4.0 SP3 Hotfix 3 Research In Motion Blackberry Enterprise Server for Domino 4.0 Research In Motion Blackberry Enterprise Server for Domino 5.0.3 MR3 Research In Motion Blackberry Enterprise Server for Domino 5.0.3 Research In Motion Blackberry Enterprise Server for Domino 5.0.2 MR1 Research In Motion Blackberry Enterprise Server for Domino 5.0.2 Research In Motion Blackberry Enterprise Server for Domino 5.0.1 Research In Motion Blackberry Enterprise Server for Domino 5.0 Research In Motion Blackberry Enterprise Server for Domino 4.1.7 Research In Motion Blackberry Enterprise Server for Domino 4.1.4 Research In Motion Blackberry Enterprise Server for Domino 4.1 SP3 Research In Motion Blackberry Enterprise Server for Domino 4.0 SP3 Hotfix 4 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.3 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.2 MR1 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.2 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.1 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.0 Research In Motion Blackberry Enterprise Server Express for Exchange 4.1.4 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.3 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.2 MR1 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.2 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.0 Research In Motion Blackberry Enterprise Server Express for Domino 4.1.4 Research In Motion Blackberry Enterprise Server 4.1.6 MR5 Research In Motion Blackberry Enterprise Server 4.1.6 MR4 Research In Motion Blackberry Enterprise Server 4.1.6 Research In Motion Blackberry Enterprise Server 4.1.5 Research In Motion Blackberry Enterprise Server 4.1.4 Research In Motion Blackberry Enterprise Server 4.1.3 Research In Motion Blackberry Enterprise Server 4.0.3 Research In Motion Blackberry Enterprise Server 4.0 Research In Motion Blackberry Enterprise Server 2.0 .0.65 Research In Motion Blackberry Enterprise Server 4.1 Research In Motion Blackberry Enterprise Server 4.0 SP3 Research In Motion Blackberry Enterprise Server 0 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Enterprise Linux Desktop version 4 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Pardus Linux 2011 0 Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 SP3 Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 SP2 Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 SP1 Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 LibTIFF LibTIFF 3.9.4 LibTIFF LibTIFF 3.9.3 LibTIFF LibTIFF 3.9.2 LibTIFF LibTIFF 3.9.2 LibTIFF LibTIFF 3.9 LibTIFF LibTIFF 3.8.2 LibTIFF LibTIFF 3.8.1 LibTIFF LibTIFF 3.8.1 LibTIFF LibTIFF 3.8 LibTIFF LibTIFF 3.7.4 LibTIFF LibTIFF 3.7.3 LibTIFF LibTIFF 3.7.2 LibTIFF LibTIFF 3.7.1 LibTIFF LibTIFF 3.7.1 LibTIFF LibTIFF 3.7 LibTIFF LibTIFF 3.7 LibTIFF LibTIFF 3.6.1 LibTIFF LibTIFF 3.6.1 LibTIFF LibTIFF 3.6 .0 LibTIFF LibTIFF 3.6 LibTIFF LibTIFF 3.5.7 LibTIFF LibTIFF 3.5.7 LibTIFF LibTIFF 3.5.6 LibTIFF LibTIFF 3.5.5 LibTIFF LibTIFF 3.5.4 LibTIFF LibTIFF 3.5.3 LibTIFF LibTIFF 3.5.2 LibTIFF LibTIFF 3.5.2 LibTIFF LibTIFF 3.5.1 LibTIFF LibTIFF 3.4 LibTIFF LibTIFF 4.0 Beta6 LibTIFF LibTIFF 4.0 Beta5 LibTIFF LibTIFF 4.0 Beta4 LibTIFF LibTIFF 4.0 Beta3 LibTIFF LibTIFF 4.0 Beta2 LibTIFF LibTIFF 4.0 Beta1 LibTIFF LibTIFF 4.0 Alpha LibTIFF LibTIFF 4.0 LibTIFF LibTIFF 3.9.4 LibTIFF LibTIFF 3.9.2-5.2.1 LibTIFF LibTIFF 3.9.1 LibTIFF LibTIFF 3.9.0 Beta LibTIFF LibTIFF 3.9 LibTIFF LibTIFF 3.7.3 LibTIFF LibTIFF 3.7.2-7 LibTIFF LibTIFF 3.7.2 LibTIFF LibTIFF 3.7.0 Beta2 LibTIFF LibTIFF 3.7.0 Beta LibTIFF LibTIFF 3.7.0 Alpha LibTIFF LibTIFF 3.6.0 Beta2 LibTIFF LibTIFF 3.6.0 Beta LibTIFF LibTIFF 3.5.7 Beta LibTIFF LibTIFF 3.5.7 Alpha4 LibTIFF LibTIFF 3.5.7 Alpha3 LibTIFF LibTIFF 3.5.7 Alpha2 LibTIFF LibTIFF 3.5.7 Alpha LibTIFF LibTIFF 3.5.6 Beta LibTIFF LibTIFF 3.5.5 LibTIFF LibTIFF 3.5.4 LibTIFF LibTIFF 3.5.3 LibTIFF LibTIFF 3.5.1 LibTIFF LibTIFF 3.4 Beta37 LibTIFF LibTIFF 3.4 Beta36 LibTIFF LibTIFF 3.4 Beta35 LibTIFF LibTIFF 3.4 Beta34 LibTIFF LibTIFF 3.4 Beta32 LibTIFF LibTIFF 3.4 Beta31 LibTIFF LibTIFF 3.4 Beta29 LibTIFF LibTIFF 3.4 Beta28 LibTIFF LibTIFF 3.4 Beta24 LibTIFF LibTIFF 3.4 Beta18 LibTIFF LibTIFF 3.4 HP OpenCall MultiService Controller 4.0 SP3 HP OpenCall MultiService Controller 4.0 SP2 HP OpenCall MultiService Controller 4.0 eSignal eSignal 6.0.2 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Avaya Proactive Contact 4.1.2 Avaya Proactive Contact 4.1.1 Avaya Proactive Contact 5.0 Avaya Proactive Contact 4.2.1 Avaya Proactive Contact 4.2 Avaya Proactive Contact 4.1 Avaya Proactive Contact 4.0.1 Avaya Proactive Contact 4.0 Avaya Messaging Storage Server 5.2.8 Avaya Messaging Storage Server 5.2.2 Avaya Messaging Storage Server 5.2 SP3 Avaya Messaging Storage Server 5.2 SP2 Avaya Messaging Storage Server 5.2 SP1 Avaya Messaging Storage Server 5.2 Avaya Messaging Storage Server 4.0 Avaya Message Networking 5.2.1 Avaya Message Networking 5.2.3 Avaya Message Networking 5.2.2 Avaya Message Networking 5.2 Avaya Message Networking 3.1 Avaya IQ 4.1 Avaya IQ 5.2 Avaya IQ 5.1 Avaya IQ 5 Avaya IQ 4.2 Avaya IQ 4.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Application Server 5300 SIP Core 2.1 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Server 5300 SIP Core 1.0 Apple Safari 4.1.2 for Windows Apple Safari 4.0.5 for Windows Apple Safari 4.0.5 Apple Safari 4.0.4 for Windows Apple Safari 4.0.4 Apple Safari 4.0.3 for Windows Apple Safari 4.0.3 Apple Safari 4.0.2 for Windows Apple Safari 4.0.2 Apple Safari 4.0.1 Apple Safari 5.0.3 for Windows Apple Safari 5.0.3 Apple Safari 5.0.2 for Windows Apple Safari 5.0.2 Apple Safari 5.0.1 for Windows Apple Safari 5.0.1 Apple Safari 5.0 for Windows Apple Safari 5.0 Apple Safari 4.1.3 for Windows Apple Safari 4.1.3 Apple Safari 4.1.2 Apple Safari 4.1.1 Apple Safari 4.1 Apple Safari 4.0 Beta Apple Safari 4.0 Apple Safari 4 for Windows Apple Safari 4 Beta Apple Safari 4 Apple Mobile Safari 0 Apple Mac OS X Server 10.6.6 Apple Mac OS X Server 10.6.5 Apple Mac OS X Server 10.6.4 Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac OS X Server 10.5.8 Apple Mac OS X Server 10.5.7 Apple Mac OS X Server 10.5.6 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.5 Apple Mac OS X Server 10.6 Apple Mac OS X Server 10.5 Apple Mac OS X 10.6.5 Apple Mac OS X 10.6.4 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac OS X 10.5.8 Apple Mac OS X 10.5.7 Apple Mac OS X 10.5.6 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.5 Apple Mac OS X 10.6 Apple Mac OS X 10.5 Apple iTunes 9.2.1 Apple iTunes 9.0.2 Apple iTunes 9.0.1 .8 Apple iTunes 9.0.1 Apple iTunes 9.0 Apple iTunes 7.3.2 Apple iTunes 7.3.1 Apple iTunes 7.3 Apple iTunes 7.0.2 Apple iTunes 6.0.5 Apple iTunes 6.0.4 Apple iTunes 6.0.3 Apple iTunes 6.0.1 Apple iTunes 6.0 Apple iTunes 5.0 Apple iTunes 4.8 Apple iTunes 4.7.1 Apple iTunes 4.7 Apple iTunes 4.6 Apple iTunes 4.5 Apple iTunes 4.2 .72 Apple iTunes 9.2 Apple iTunes 9.1 Apple iTunes 8.2 Apple iTunes 8.1 Apple iTunes 8.0.2.20 Apple iTunes 8.0 Apple iTunes 7.4 Apple iTunes 10.1 Apple iTunes 10 Apple iPod Touch 0 Apple iPhone 0 Apple iPad 0 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 4.3.5 Apple iOS 4.3.4 Apple iOS 4.3.3 Apple iOS 4.3.2 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2.9 Apple iOS 4.2.8 Apple iOS 4.2.7 Apple iOS 4.2.6 Apple iOS 4.2.5 Apple iOS 4.2.10 Apple iOS 4.2 beta Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 2.1 Apple iOS 2.0 Apple Apple TV 4.3 Apple Apple TV 4.2 Apple Apple TV 4.1 Apple Apple TV 4.0 Apple Apple TV 2.1 Apple Apple TV 1.0 |
| Not Vulnerable: |
Apple Safari 5.0.4 for Windows Apple Safari 5.0.4 Apple Mac Os X Server 10.6.7 Apple iTunes 10.2 Apple iOS 5 Apple iOS 4.3 Apple Apple TV 4.4 Apple Apple TV 4.2 |
Discussion
libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability
libTIFF is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
NOTE: This BID was previously titled 'Apple iTunes libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability' but has been changed to better reflect the affected library.
Note (March 30, 2011): This issue has not been patched as expected.
libTIFF is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
NOTE: This BID was previously titled 'Apple iTunes libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability' but has been changed to better reflect the affected library.
Note (March 30, 2011): This issue has not been patched as expected.
Exploit / POC
libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
Ubuntu Ubuntu Linux 10.04 powerpc
Ubuntu Ubuntu Linux 9.10 amd64
Mandriva Linux Mandrake 2009.0 x86_64
Apple Safari 5.0.3 for Windows
MandrakeSoft Enterprise Server 5
Apple iTunes 10.1
Slackware Linux 10.0
Apple Mac OS X Server 10.6.6
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
-
Slackware libtiff-3.8.2-i486-5_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ libtiff-3.8.2-i486-5_slack12.2.tgz
Ubuntu Ubuntu Linux 10.04 powerpc
-
Ubuntu libtiff-doc_3.9.2-2ubuntu0.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-doc_3.9.2-2 ubuntu0.4_all.deb -
Ubuntu libtiff-opengl_3.9.2-2ubuntu0.4_powerpc.deb
http://ports.ubuntu.com/pool/universe/t/tiff/libtiff-opengl_3.9.2-2ubu ntu0.4_powerpc.deb -
Ubuntu libtiff-tools_3.9.2-2ubuntu0.4_powerpc.deb
http://ports.ubuntu.com/pool/main/t/tiff/libtiff-tools_3.9.2-2ubuntu0. 4_powerpc.deb -
Ubuntu libtiff4-dev_3.9.2-2ubuntu0.4_powerpc.deb
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4-dev_3.9.2-2ubuntu0.4 _powerpc.deb -
Ubuntu libtiff4_3.9.2-2ubuntu0.4_powerpc.deb
http://ports.ubuntu.com/pool/main/t/tiff/libtiff4_3.9.2-2ubuntu0.4_pow erpc.deb -
Ubuntu libtiffxx0c2_3.9.2-2ubuntu0.4_powerpc.deb
http://ports.ubuntu.com/pool/main/t/tiff/libtiffxx0c2_3.9.2-2ubuntu0.4 _powerpc.deb
Ubuntu Ubuntu Linux 9.10 amd64
-
Ubuntu libtiff-doc_3.8.2-13ubuntu0.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-doc_3.8.2-1 3ubuntu0.4_all.deb -
Ubuntu libtiff-opengl_3.8.2-13ubuntu0.4_amd64.deb
http://security.ubuntu.com/ubuntu/pool/universe/t/tiff/libtiff-opengl_ 3.8.2-13ubuntu0.4_amd64.deb -
Ubuntu libtiff-tools_3.8.2-13ubuntu0.4_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff-tools_3.8.2 -13ubuntu0.4_amd64.deb -
Ubuntu libtiff4-dev_3.8.2-13ubuntu0.4_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4-dev_3.8.2- 13ubuntu0.4_amd64.deb -
Ubuntu libtiff4_3.8.2-13ubuntu0.4_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiff4_3.8.2-13ub untu0.4_amd64.deb -
Ubuntu libtiffxx0c2_3.8.2-13ubuntu0.4_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/t/tiff/libtiffxx0c2_3.8.2- 13ubuntu0.4_amd64.deb
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva lib64tiff3-3.8.2-12.4mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64tiff3-devel-3.8.2-12.4mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64tiff3-static-devel-3.8.2-12.4mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva libtiff-progs-3.8.2-12.4mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Apple Safari 5.0.3 for Windows
-
Apple APPLE-SA-2011-03-09-2 Safari_Setup.exe
Safari for Windows 7, Vista or XP from the Microsoft Choice Screen
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2011-03-09-2 SafariQuickTimeSetup.exe
Safari+QuickTime for Windows 7, Vista or XP
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2011-03-09-2 SafariSetup.exe
Safari for Windows 7, Vista or XP
http://www.apple.com/safari/download/
MandrakeSoft Enterprise Server 5
-
Mandriva libtiff-progs-3.8.2-12.4mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libtiff3-3.8.2-12.4mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libtiff3-devel-3.8.2-12.4mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libtiff3-static-devel-3.8.2-12.4mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/
Apple iTunes 10.1
-
Apple APPLE-SA-2011-03-02-1 iTunes64Setup.exe
For 64-bit Windows XP / Vista / Windows 7
http://www.apple.com/itunes/download/ -
Apple APPLE-SA-2011-03-02-1 iTunesSetup.exe
For Windows XP / Vista / Windows 7
http://www.apple.com/itunes/download/ -
Apple iTunes10.2.dmg
for Mac OS X
http://www.apple.com/itunes/download/
Slackware Linux 10.0
-
Slackware libtiff-3.8.2-i486-3_slack10.0.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ libtiff-3.8.2-i486-3_slack10.0.tgz
Apple Mac OS X Server 10.6.6
-
Apple MacOSXServerUpd10.6.7.dmg
For Mac OS X Server v10.6.6
http://www.apple.com/support/downloads/
References
libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability
References:
References:
- Bug 2297 - Regression when reading CCITTFAX4 files due to fix for CVE-2011-0192 (Even Rouault)
- iTunes Homepage (Apple)
- LibTIFF Homepage (LibTIFF)
- ASA-2011-091 libtiff security update (RHSA-2011-0318) (Avaya)
- Vulnerabilities in BlackBerry Enterprise Server components that process images c (Research In Motion)