Skip to navigation

Security Advisory kdegraphics security update

Advisory: RHSA-2006:0648-4
Type: Security Advisory
Severity: Moderate
Issued on: 2006-08-28
Last updated on: 2006-08-28
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Enterprise Linux WS (v. 3)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
CVEs (cve.mitre.org): CVE-2006-2024
CVE-2006-2025
CVE-2006-2026
CVE-2006-3459
CVE-2006-3460
CVE-2006-3461
CVE-2006-3462
CVE-2006-3463
CVE-2006-3464
CVE-2006-3465

Details

Updated kdegraphics packages that fix several security flaws in kfax are
now available for Red Hat Enterprise Linux 2.1, and 3.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

The kdegraphics package contains graphics applications for the K Desktop
Environment.

Tavis Ormandy of Google discovered a number of flaws in libtiff during a
security audit. The kfax application contains a copy of the libtiff code
used for parsing TIFF files and is therefore affected by these flaws.
An attacker who has the ability to trick a user into opening a malicious
TIFF file could cause kfax to crash or possibly execute arbitrary code.
(CVE-2006-3459, CVE-2006-3460, CVE-2006-3461, CVE-2006-3462, CVE-2006-3463,
CVE-2006-3464, CVE-2006-3465)

Red Hat Enterprise Linux 4 is not vulnerable to these issues as kfax uses
the shared libtiff library which has been fixed in a previous update.

Users of kfax should upgrade to these updated packages, which contain
backported patches and are not vulnerable to this issue.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via Red Hat Network. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
kdegraphics-3.1.3-3.10.src.rpm
File outdated by:  RHBA-2007:0453
    MD5: ef88572cbd568315228054297655ef86
 
IA-32:
kdegraphics-3.1.3-3.10.i386.rpm
File outdated by:  RHBA-2007:0453
    MD5: 854050e9b33c97244bb7d7c9e5448257
kdegraphics-devel-3.1.3-3.10.i386.rpm
File outdated by:  RHBA-2007:0453
    MD5: 5da00f57f88c1f99308ede725c43c73c
 
x86_64:
kdegraphics-3.1.3-3.10.x86_64.rpm
File outdated by:  RHBA-2007:0453
    MD5: ce51d29598cdc0ac9aa433a669f37d7f
kdegraphics-devel-3.1.3-3.10.x86_64.rpm
File outdated by:  RHBA-2007:0453
    MD5: f83a0c0a9cedf3728b6cc02f12cac6e6
 
Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics/2.2.2-4.4/SRPMS/kdegraphics-2.2.2-4.4.src.rpm
Missing file
    MD5: 7e02f00c6f0f04f4b2d344a4ec023d8f
 
IA-32:
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics/2.2.2-4.4/i386/kdegraphics-2.2.2-4.4.i386.rpm
Missing file
    MD5: 95b171e3e34fb770f40ca342201b8530
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics-devel/2.2.2-4.4/i386/kdegraphics-devel-2.2.2-4.4.i386.rpm
Missing file
    MD5: 92d41638599ce40f99bd4dae53d4557d
 
IA-64:
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics/2.2.2-4.4/ia64/kdegraphics-2.2.2-4.4.ia64.rpm
Missing file
    MD5: b60111c884c0c11fe38c014fd2aa20a4
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics-devel/2.2.2-4.4/ia64/kdegraphics-devel-2.2.2-4.4.ia64.rpm
Missing file
    MD5: 8d3017d74b4c39ca38c6840127134b7d
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
kdegraphics-3.1.3-3.10.src.rpm
File outdated by:  RHBA-2007:0453
    MD5: ef88572cbd568315228054297655ef86
 
IA-32:
kdegraphics-3.1.3-3.10.i386.rpm
File outdated by:  RHBA-2007:0453
    MD5: 854050e9b33c97244bb7d7c9e5448257
kdegraphics-devel-3.1.3-3.10.i386.rpm
File outdated by:  RHBA-2007:0453
    MD5: 5da00f57f88c1f99308ede725c43c73c
 
IA-64:
kdegraphics-3.1.3-3.10.ia64.rpm
File outdated by:  RHBA-2007:0453
    MD5: 26bd834fd42ee5aeeab12cb1e7255f4f
kdegraphics-devel-3.1.3-3.10.ia64.rpm
File outdated by:  RHBA-2007:0453
    MD5: 7186b1f5ca78824f67b73cf9b83351d7
 
PPC:
kdegraphics-3.1.3-3.10.ppc.rpm
File outdated by:  RHBA-2007:0453
    MD5: 9f6cdd9650db6608f972c42c76e8a4de
kdegraphics-devel-3.1.3-3.10.ppc.rpm
File outdated by:  RHBA-2007:0453
    MD5: b452e2ef7748b702aa75b10dcc33f17c
 
s390:
kdegraphics-3.1.3-3.10.s390.rpm
File outdated by:  RHBA-2007:0453
    MD5: 866768918b02cd3601a304a59d15ad51
kdegraphics-devel-3.1.3-3.10.s390.rpm
File outdated by:  RHBA-2007:0453
    MD5: a3055e2cf71f6e7620a9c84a6058be7f
 
s390x:
kdegraphics-3.1.3-3.10.s390x.rpm
File outdated by:  RHBA-2007:0453
    MD5: 522c7089c601e9ed8d01e478503a795a
kdegraphics-devel-3.1.3-3.10.s390x.rpm
File outdated by:  RHBA-2007:0453
    MD5: 893a3ad832cfdc2e65ec585536717ca0
 
x86_64:
kdegraphics-3.1.3-3.10.x86_64.rpm
File outdated by:  RHBA-2007:0453
    MD5: ce51d29598cdc0ac9aa433a669f37d7f
kdegraphics-devel-3.1.3-3.10.x86_64.rpm
File outdated by:  RHBA-2007:0453
    MD5: f83a0c0a9cedf3728b6cc02f12cac6e6
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics/2.2.2-4.4/SRPMS/kdegraphics-2.2.2-4.4.src.rpm
Missing file
    MD5: 7e02f00c6f0f04f4b2d344a4ec023d8f
 
IA-32:
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics/2.2.2-4.4/i386/kdegraphics-2.2.2-4.4.i386.rpm
Missing file
    MD5: 95b171e3e34fb770f40ca342201b8530
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics-devel/2.2.2-4.4/i386/kdegraphics-devel-2.2.2-4.4.i386.rpm
Missing file
    MD5: 92d41638599ce40f99bd4dae53d4557d
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
kdegraphics-3.1.3-3.10.src.rpm
File outdated by:  RHBA-2007:0453
    MD5: ef88572cbd568315228054297655ef86
 
IA-32:
kdegraphics-3.1.3-3.10.i386.rpm
File outdated by:  RHBA-2007:0453
    MD5: 854050e9b33c97244bb7d7c9e5448257
kdegraphics-devel-3.1.3-3.10.i386.rpm
File outdated by:  RHBA-2007:0453
    MD5: 5da00f57f88c1f99308ede725c43c73c
 
IA-64:
kdegraphics-3.1.3-3.10.ia64.rpm
File outdated by:  RHBA-2007:0453
    MD5: 26bd834fd42ee5aeeab12cb1e7255f4f
kdegraphics-devel-3.1.3-3.10.ia64.rpm
File outdated by:  RHBA-2007:0453
    MD5: 7186b1f5ca78824f67b73cf9b83351d7
 
x86_64:
kdegraphics-3.1.3-3.10.x86_64.rpm
File outdated by:  RHBA-2007:0453
    MD5: ce51d29598cdc0ac9aa433a669f37d7f
kdegraphics-devel-3.1.3-3.10.x86_64.rpm
File outdated by:  RHBA-2007:0453
    MD5: f83a0c0a9cedf3728b6cc02f12cac6e6
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics/2.2.2-4.4/SRPMS/kdegraphics-2.2.2-4.4.src.rpm
Missing file
    MD5: 7e02f00c6f0f04f4b2d344a4ec023d8f
 
IA-32:
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics/2.2.2-4.4/i386/kdegraphics-2.2.2-4.4.i386.rpm
Missing file
    MD5: 95b171e3e34fb770f40ca342201b8530
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics-devel/2.2.2-4.4/i386/kdegraphics-devel-2.2.2-4.4.i386.rpm
Missing file
    MD5: 92d41638599ce40f99bd4dae53d4557d
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
kdegraphics-3.1.3-3.10.src.rpm
File outdated by:  RHBA-2007:0453
    MD5: ef88572cbd568315228054297655ef86
 
IA-32:
kdegraphics-3.1.3-3.10.i386.rpm
File outdated by:  RHBA-2007:0453
    MD5: 854050e9b33c97244bb7d7c9e5448257
kdegraphics-devel-3.1.3-3.10.i386.rpm
File outdated by:  RHBA-2007:0453
    MD5: 5da00f57f88c1f99308ede725c43c73c
 
IA-64:
kdegraphics-3.1.3-3.10.ia64.rpm
File outdated by:  RHBA-2007:0453
    MD5: 26bd834fd42ee5aeeab12cb1e7255f4f
kdegraphics-devel-3.1.3-3.10.ia64.rpm
File outdated by:  RHBA-2007:0453
    MD5: 7186b1f5ca78824f67b73cf9b83351d7
 
x86_64:
kdegraphics-3.1.3-3.10.x86_64.rpm
File outdated by:  RHBA-2007:0453
    MD5: ce51d29598cdc0ac9aa433a669f37d7f
kdegraphics-devel-3.1.3-3.10.x86_64.rpm
File outdated by:  RHBA-2007:0453
    MD5: f83a0c0a9cedf3728b6cc02f12cac6e6
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics/2.2.2-4.4/SRPMS/kdegraphics-2.2.2-4.4.src.rpm
Missing file
    MD5: 7e02f00c6f0f04f4b2d344a4ec023d8f
 
IA-64:
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics/2.2.2-4.4/ia64/kdegraphics-2.2.2-4.4.ia64.rpm
Missing file
    MD5: b60111c884c0c11fe38c014fd2aa20a4
ftp://updates.redhat.com/rhn/repository/NULL/kdegraphics-devel/2.2.2-4.4/ia64/kdegraphics-devel-2.2.2-4.4.ia64.rpm
Missing file
    MD5: 8d3017d74b4c39ca38c6840127134b7d
 

Bugs fixed (see bugzilla for more information)

201313 - CVE-2006-3459 kfax affected by libtiff flaws (CVE-2006-3460 CVE-2006-3461 CVE-2006-3462 CVE-2006-3463 CVE-2006-3464 CVE-2006-3465)


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/