Revision Date: | 2005-04-14 | Version: | 502 |
Title: | RHSA-2005:021: kdegraphics security update (Moderate) |
Description: | The kdegraphics package contains graphics applications for the K Desktop Environment.
During a source code audit, Chris Evans discovered a number of integer overflow bugs that affect libtiff. The kfax application contains a copy of the libtiff code used for parsing TIFF files and is therefore affected by these bugs. An attacker who has the ability to trick a user into opening a malicious TIFF file could cause kfax to crash or possibly execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0886 and CAN-2004-0804 to these issues.
Additionally, a number of buffer overflow bugs that affect libtiff have been found. The kfax application contains a copy of the libtiff code used for parsing TIFF files and is therefore affected by these bugs. An attacker who has the ability to trick a user into opening a malicious TIFF file could cause kfax to crash or possibly execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0803 to this issue.
Users of kfax should upgrade to these updated packages, which contain backported patches and are not vulnerable to this issue.
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | CVE-2004-0803 CVE-2004-0804 CVE-2004-0886 CVE-2004-1307 CVE-2004-1308 RHSA-2005:021-01
|
Platform(s): | Red Hat Enterprise Linux 3
| Product(s): | |
Definition Synopsis |
Red Hat Enterprise Linux 3 is installed AND Package Information
kdegraphics is earlier than 7:3.1.3-3.7
AND kdegraphics is signed with Red Hat master key
OR
kdegraphics-devel is earlier than 7:3.1.3-3.7
AND kdegraphics-devel is signed with Red Hat master key
|