让您全面了解并上手亿速云产品
常见入门级使用教程
对外 API 开发文档中心
您历史提交的工单
您的每一条意见,我们都严谨处理
您的每一条建议,我们都认真对待
CNNVD-ID编号 | CNNVD-200604-457 | CVE编号 | CVE-2006-2024 |
发布时间 | 2006-04-25 | 更新时间 | 2006-04-26 |
漏洞类型 | 其他 | 漏洞来源 | Tavis Ormandy is credited with the discovery of these vulnerabilities. |
危险等级 | 中危 | 威胁类型 | 远程 |
厂商 | libtiff |
libtiff 3.8.1之前的版本中存在多个漏洞。这使得依赖于上下文的攻击者可以借助于TIFF图像造成拒绝服务,该TIFF图像触发了(1)(a) tif_dirread.c中的TIFFFetchAnyArray函数中的错误;(2)(b) tif_lzw.c、(c) tif_pixarlog.c和(d) tif_zip.c 中的某些\"codec清理方法\"中的错误;(3)不恰当的重置(e) tif_ipeg.c、tif_pixarlog.c、(f)tif_fax3.c和tif_zip.c中的清理函数中setfield和getfield方法而导致的错误。
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Sun Solaris 8
Sun 139093-01
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -139093-01-1
Sun Solaris 10
Sun 119900-03
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -119900-03-1
Sun Solaris 10_x86
Sun 119901-03
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -119901-03-1
Sun Solaris 9
Sun 125673-01
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125673-01-1
Sun Solaris 9_x86
Sun 125674-01
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125674-01-1
Sun Solaris 8_x86
Sun 139094-01
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -139094-01-1
LibTIFF LibTIFF 3.5.5
Debian libtiff-tools_3.5.5-7woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5. 5-7woody1_alpha.deb
Debian libtiff-tools_3.5.5-7woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5. 5-7woody1_arm.deb
Debian libtiff-tools_3.5.5-7woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5. 5-7woody1_hppa.deb
Debian libtiff-tools_3.5.5-7woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5. 5-7woody1_i386.deb
Debian libtiff-tools_3.5.5-7woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5. 5-7woody1_ia64.deb
Debian libtiff-tools_3.5.5-7woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5. 5-7woody1_m68k.deb
Debian libtiff-tools_3.5.5-7woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5. 5-7woody1_mips.deb
Debian libtiff-tools_3.5.5-7woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5. 5-7woody1_mipsel.deb
Debian libtiff-tools_3.5.5-7woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5. 5-7woody1_powerpc.deb
Debian libtiff-tools_3.5.5-7woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5. 5-7woody1_s390.deb
Debian libtiff-tools_3.5.5-7woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff-tools_3.5. 5-7woody1_sparc.deb
Debian libtiff3g-dev_3.5.5-7woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5. 5-7woody1_alpha.deb
Debian libtiff3g-dev_3.5.5-7woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5. 5-7woody1_arm.deb
Debian libtiff3g-dev_3.5.5-7woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5. 5-7woody1_hppa.deb
Debian libtiff3g-dev_3.5.5-7woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5. 5-7woody1_i386.deb
Debian libtiff3g-dev_3.5.5-7woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5. 5-7woody1_ia64.deb
Debian libtiff3g-dev_3.5.5-7woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5. 5-7woody1_m68k.deb
Debian libtiff3g-dev_3.5.5-7woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5. 5-7woody1_mips.deb
Debian libtiff3g-dev_3.5.5-7woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tiff/libtiff3g-dev_3.5. 5-7woody1_mipsel.deb
Debian libtiff3g-dev_3.5.5-7woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woo
来源: bugzilla.redhat.com
链接:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189933
来源: MISC
来源: XF
名称: libtiff-tifffetchanyarray-dos(26133)
来源: UBUNTU
名称: USN-277-1
链接:http://www.ubuntulinux.org/support/documentation/usn/usn-277-1
来源: TRUSTIX
名称: 2006-0024
来源: BID
名称: 17730
来源: REDHAT
名称: RHSA-2006:0425
来源: SUSE
名称: SUSE-SR:2006:009
链接:http://www.novell.com/linux/security/advisories/2006_04_28.html
来源: MANDRIVA
名称: MDKSA-2006:082
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:082
来源: GENTOO
名称: GLSA-200605-17
链接:http://www.gentoo.org/security/en/glsa/glsa-200605-17.xml
来源: VUPEN
名称: ADV-2006-1563
来源: DEBIAN
名称: DSA-1054
来源: support.avaya.com
链接:http://support.avaya.com/elmodocs2/security/ASA-2006-119.htm
来源: SUNALERT
名称: 201332
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-66-201332-1
来源: SUNALERT
名称: 103099
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-103099-1
来源: SECUNIA
名称: 20667
来源: SECUNIA
名称: 20345
来源: SECUNIA
名称: 20210
来源: SECUNIA
名称: 20023
来源: SECUNIA
名称: 20021
来源: SECUNIA
名称: 19964
来源: SECUNIA
名称: 19949
来源: SECUNIA
名称: 19936
来源: SECUNIA
名称: 19897
来源: SECUNIA
名称: 19851
来源: SECUNIA
名称: 19838
来源: MANDRIVA
名称: MDKSA-2006:082
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:082