Summary
The remote host is missing updates announced in
advisory GLSA 200410-11.
Solution
All tiff library users should upgrade to the latest version:
# emerge sync
# emerge -pv '>=media-libs/tiff-3.6.1-r2'
# emerge '>=media-libs/tiff-3.6.1-r2'
xv makes use of the tiff library and needs to be recompiled to receive the new patched version of the library. All xv users should also upgrade to the latest version:
# emerge sync
# emerge -pv '>=media-gfx/xv-3.10a-r8'
# emerge '>=media-gfx/xv-3.10a-r8'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200410-11
Insight
Multiple heap-based overflows have been found in the tiff library image decoding routines, potentially allowing to execute arbitrary code with the rights of the user viewing a malicious image.
Severity
Classification
-
CVE CVE-2004-0803 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities