Summary
The remote host is missing an update to tiff
announced via advisory USN-797-1.
Solution
The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS:
libtiff4 3.7.4-1ubuntu3.4
Ubuntu 8.04 LTS:
libtiff4 3.8.2-7ubuntu3.2
Ubuntu 8.10:
libtiff4 3.8.2-11ubuntu0.8.10.1
Ubuntu 9.04:
libtiff4 3.8.2-11ubuntu0.9.04.1
In general, a standard system upgrade is sufficient to effect the necessary changes.
https://secure1.securityspace.com/smysecure/catid.html?in=USN-797-1
Insight
It was discovered that the TIFF library did not correctly handle certain malformed TIFF images. If a user or automated system were tricked into processing a malicious image, a remote attacker could cause an application linked against libtiff to crash, leading to a denial of service.
Severity
Classification
-
CVE CVE-2009-2285 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:P/I:N/A:N
Related Vulnerabilities