Fwd: Linux distributors warn of security vulnerabilities, issue fixes

Lennart Sorensen lsorense-1wCw9BSqJbv44Nm34jS7GywD8/FfD2ys at public.gmane.org
Mon Jan 24 16:02:33 UTC 2005


On Sun, Jan 23, 2005 at 04:34:04PM -0500, Rick Tomaschuk wrote:
[snip]
> Red Hat had two advisories, warning that users' systems could be 
> compromised by maliciously altered PDF or TIFF image files. One 
> concerned an update that fixes a potential vulnerability in the 
> LibTIFF library on Red Hat systems. The vulnerability could 
> allow a malicious user to execute arbitrary code on a Linux 
> machine via a specially crafted TIFF image file. An application 
> linked to the LibTIFF library could be tricked into running 
> code. The vulnerabilities affect several versions of Red Hat 
> Enterprise Server, Advanced Server and Advanced Workstation for 
> 32- and 64-bit Intel processors.
[snip]

Hmm, when did they actually fix these and release the fixes.  I thought
these were fixed in late December (at least that is when Debian released
fixes for these problems).  Doesn't seem much like news a month later.
:)

Lennart Sorensen
--
The Toronto Linux Users Group.      Meetings: http://tlug.ss.org
TLUG requests: Linux topics, No HTML, wrap text below 80 columns
How to UNSUBSCRIBE: http://tlug.ss.org/subscribe.shtml





More information about the Legacy mailing list