Univention Bugzilla – Bug 33832
tiff: Multiple issues (3.2)
Last modified: 2016-06-22 15:05:28 CEST
+++ This bug was initially created as a clone of Bug #33831 +++ Buffer overflow in gif2tiff (CVE-2013-4243) No upstream patch is available so far.
Buffer overflow in bmp2tiff (CVE-2014-9330)
Multiple out of bound reads in processing TIFF files (CVE-2014-8127) Multiple out of bound writes in processing TIFF files (CVE-2014-8128) Multiple out of bound reads/writes in processing TIFF files (CVE-2014-8129) Multiple NULL pointer dereferences in processing TIFF files (CVE-2014-8130)
Denial of service by accessing uninitialised memory (CVE-2015-1547, CVE-2014-9655)
Fixed in 3.9.4-5+squeeze12: * Buffer overflow in gif2tiff (CVE-2013-4243) * Buffer overflow in bmp2tiff (CVE-2014-9330) * Multiple out of bound reads in processing TIFF files (CVE-2014-8127) * Multiple out of bound writes in processing TIFF files (CVE-2014-8128) * Multiple out of bound reads/writes in processing TIFF files (CVE-2014-8129) * Denial of service by accessing uninitialised memory (CVE-2014-9655) No fix yet for: * uninitialized memory in NeXTDecode (CVE-2015-1547) [patch available] * Denial of service by accessing uninitialised memory/divide by zero (CVE-2014-8130) [marked as unimportant in Debian]
* Out-of-bounds Read (CVE-2015-8665) * Out-of-bounds read in CIE Lab image format (CVE-2015-8683)
Fixed in 3.9.4-5+squeeze13: * Out-of-bounds Read (CVE-2015-8665) * Out-of-bounds read in CIE Lab image format (CVE-2015-8683) CVE-2015-1547 may also be fixed by the patch for CVE-2014-9655, see Debian security tracker.
Fixed in 3.9.4-5+squeeze14: * an out of bounds write in tif_luv.c (CVE-2015-8781) * other out-of-bounds writes (CVE-2015-8782) * other out-of-bounds reads (CVE-2015-8783) * potential out-of-bound write in NeXTDecode (CVE-2015-8784)
3.9.4-5+squeeze14 imported and built with fixed buildsystem version increment. Advisory: tiff.yaml
OK: advisory OK: manual functional test: # univention-install libtiff-tools caca-utils # gif2tiff -c lzw /usr/share/apache2/icons/small/rainbow.gif /tmp/rainbow.tiff # cacaview /usr/share/apache2/icons/small/rainbow.gif /tmp/rainbow.tiff
<http://errata.software-univention.de/ucs/3.2/438.html>