Oval Definition:oval:com.redhat.rhsa:def:20060648
Revision Date:2008-03-20Version:634
Title:RHSA-2006:0648: kdegraphics security update (Moderate)
Description:The kdegraphics package contains graphics applications for the K Desktop Environment.

  • Tavis Ormandy of Google discovered a number of flaws in libtiff during a security audit. The kfax application contains a copy of the libtiff code used for parsing TIFF files and is therefore affected by these flaws. An attacker who has the ability to trick a user into opening a malicious TIFF file could cause kfax to crash or possibly execute arbitrary code. (CVE-2006-3459, CVE-2006-3460, CVE-2006-3461, CVE-2006-3462, CVE-2006-3463, CVE-2006-3464, CVE-2006-3465)

    Red Hat Enterprise Linux 4 is not vulnerable to these issues as kfax uses the shared libtiff library which has been fixed in a previous update.

    Users of kfax should upgrade to these updated packages, which contain backported patches and are not vulnerable to this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-2024
    CVE-2006-2025
    CVE-2006-2026
    CVE-2006-3459
    CVE-2006-3460
    CVE-2006-3461
    CVE-2006-3462
    CVE-2006-3463
    CVE-2006-3464
    CVE-2006-3465
    RHSA-2006:0648
    RHSA-2006:0648-01
    RHSA-2006:0648-01
    Platform(s):Red Hat Enterprise Linux 3
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • kdegraphics is earlier than 7:3.1.3-3.10
  • AND kdegraphics is signed with Red Hat master key
  • kdegraphics-devel is earlier than 7:3.1.3-3.10
  • AND kdegraphics-devel is signed with Red Hat master key
  • BACK