Security Advisory Important: libtiff security and bug fix update

Advisory: RHSA-2008:0847-8
Type: Security Advisory
Severity: Important
Issued on: 2008-08-28
Last updated on: 2008-08-28
Affected Products: RHEL Desktop Workstation (v. 5 client)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux Desktop (v. 5 client)
OVAL: com.redhat.rhsa-20080847.xml
CVEs (cve.mitre.org): CVE-2008-2327

Details

Updated libtiff packages that fix a security issue and a bug are now
available for Red Hat Enterprise Linux 5.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

Multiple uses of uninitialized values were discovered in libtiff's
Lempel-Ziv-Welch (LZW) compression algorithm decoder. An attacker could
create a carefully crafted LZW-encoded TIFF file that would cause an
application linked with libtiff to crash or, possibly, execute arbitrary
code. (CVE-2008-2327)

Red Hat would like to thank Drew Yao of the Apple Product Security team for
reporting this issue.

Additionally, these updated packages fix the following bug:

* the libtiff packages included manual pages for the sgi2tiff and tiffsv
commands, which are not included in these packages. These extraneous manual
pages were removed.

All libtiff users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

RHEL Desktop Workstation (v. 5 client)

IA-32:
libtiff-devel-3.8.2-7.el5_2.2.i386.rpm     d6b4d0d80ca4f01de1fd035969e8515b
 
x86_64:
libtiff-devel-3.8.2-7.el5_2.2.i386.rpm     d6b4d0d80ca4f01de1fd035969e8515b
libtiff-devel-3.8.2-7.el5_2.2.x86_64.rpm     4d21271660e2e775deb5b6ce60f145a1
 
Red Hat Enterprise Linux (v. 5 server)

SRPMS:
libtiff-3.8.2-7.el5_2.2.src.rpm     4109278d416f8478cacbb02137e5c977
 
IA-32:
libtiff-3.8.2-7.el5_2.2.i386.rpm     d10ac2f0ad7c0c9084e46bfa43f5c2e0
libtiff-devel-3.8.2-7.el5_2.2.i386.rpm     d6b4d0d80ca4f01de1fd035969e8515b
 
IA-64:
libtiff-3.8.2-7.el5_2.2.i386.rpm     d10ac2f0ad7c0c9084e46bfa43f5c2e0
libtiff-3.8.2-7.el5_2.2.ia64.rpm     95e6290e27b99c87127b364610029590
libtiff-devel-3.8.2-7.el5_2.2.ia64.rpm     9986523c86213cdf79cd2e8bcb3b4d24
 
PPC:
libtiff-3.8.2-7.el5_2.2.ppc.rpm     c768597ab10a9f1552149d57846c5da1
libtiff-3.8.2-7.el5_2.2.ppc64.rpm     806814f0f34233f7a20a54fa501d00a5
libtiff-devel-3.8.2-7.el5_2.2.ppc.rpm     9735f22331c3279a3179da5bbe75b654
libtiff-devel-3.8.2-7.el5_2.2.ppc64.rpm     82e34f712e533286eb0b5975d6403224
 
s390x:
libtiff-3.8.2-7.el5_2.2.s390.rpm     9ae4be90e461e824a86b0657661734d7
libtiff-3.8.2-7.el5_2.2.s390x.rpm     f8389d5c3383e673706b7a3ccc704e78
libtiff-devel-3.8.2-7.el5_2.2.s390.rpm     632aa6bf536f1ee3d5e886f18102dfa4
libtiff-devel-3.8.2-7.el5_2.2.s390x.rpm     6b8040b0bfd7f20f5dddc3efda915437
 
x86_64:
libtiff-3.8.2-7.el5_2.2.i386.rpm     d10ac2f0ad7c0c9084e46bfa43f5c2e0
libtiff-3.8.2-7.el5_2.2.x86_64.rpm     5a07178954ae3cb164fecff38b8db122
libtiff-devel-3.8.2-7.el5_2.2.i386.rpm     d6b4d0d80ca4f01de1fd035969e8515b
libtiff-devel-3.8.2-7.el5_2.2.x86_64.rpm     4d21271660e2e775deb5b6ce60f145a1
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
libtiff-3.8.2-7.el5_2.2.src.rpm     4109278d416f8478cacbb02137e5c977
 
IA-32:
libtiff-3.8.2-7.el5_2.2.i386.rpm     d10ac2f0ad7c0c9084e46bfa43f5c2e0
 
x86_64:
libtiff-3.8.2-7.el5_2.2.i386.rpm     d10ac2f0ad7c0c9084e46bfa43f5c2e0
libtiff-3.8.2-7.el5_2.2.x86_64.rpm     5a07178954ae3cb164fecff38b8db122
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

458674 - CVE-2008-2327 libtiff: use of uninitialized memory in LZW decoder
460120 - [RHEL5] libtiff has unnecessary man pages.


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/