[PLSN-0006] new libexif package available

From: Peachtree Linux Security Team (security_at_peachtree.burdell.org)
Date: 04/26/05

  • Next message: Peachtree Linux Security Team: "[PLSN-0005] new cvs package available"
    Date: Mon, 25 Apr 2005 22:13:38 -0400
    To: peachlnx-security@lists.sourceforge.net, bugtraq@securityfocus.com
    
    
    

    ---------------------------------------------------------------------------
    Peachtree Linux Security Notice PLSN-0006
    April 22, 2005

    Remote DoS vulnerability in libexif
    CAN-2005-0664
    ---------------------------------------------------------------------------

    The following Peachtree Linux releases are affected:

       Peachtree Linux release 1 ("Atlanta")

    Description:

       CAN-2005-0664: Buffer overflow in the EXIF library (libexif) does not
       properly validate the structure of the EXIF tags, which allows remote
       attackers to cause a denial of service (application crash) and possibly
       execute arbitrary code via an image with a crafted EXIF tag.

    Packages:

       alpha
          8cdf8dde707c24d1817eb99f5c81b783 libexif-0.6.11.alpha.dist

       i386
          767c6442a6e76ba424b2295c422bea3c libexif-0.6.11.i686.dist

       ppc
          e5e7a516f9fc5be261c00beae0577517 libexif-0.6.11.ppc.dist

    Solution:

       Download the appropriate package for your release of Peachtree linux.
       Upgrade your system to the new package:

          distadd -u packagename

       Where package name is the name of the package file from the list above.

    -- 
    Peachtree Linux Security Team
    http://peachtree.burdell.org/
    
    



  • Next message: Peachtree Linux Security Team: "[PLSN-0005] new cvs package available"

    Relevant Pages

    • [PLSN-0001] - Multiple PHP vulnerabilities
      ... Peachtree Linux Security Notice PLSN-0001 ... Remote code execution and remote DoS vulnerability in PHP ... Download the appropriate package for your release of Peachtree Linux. ...
      (Bugtraq)
    • [PLSN-0001] - Multiple vulnerabilities in Gaim
      ... Peachtree Linux Security Notice PLSN-0001 ... Remote code execution and remote DoS vulnerability in PHP ... Download the appropriate package for your release of Peachtree Linux. ...
      (Bugtraq)
    • [PLSN-0004] - Buffer overflow in PostgreSQL
      ... Peachtree Linux Security Notice PLSN-0004 ... Buffer overflow in PL/PGSQL parser allowing database users to run arbitrary ... to run SQL statements to execute arbitrary code as the pgsql user. ... Download the appropriate package for your release of Peachtree linux. ...
      (Bugtraq)
    • [PLSN-0003] - Remote exploits in MPlayer
      ... Peachtree Linux Security Notice PLSN-0003 ... A buffer overflow vulnerability exists in the RTSP stream module, ... which could allow malicious servers of MMS or TCP streams to execute ... Download the appropriate package for your release of Peachtree Linux. ...
      (Bugtraq)
    • [PLSN-0003] - Remote exploits in mplayer
      ... Peachtree Linux Security Notice PLSN-0003 ... A buffer overflow vulnerability exists in the RTSP stream module, ... which could allow malicious servers of MMS or TCP streams to execute ... Download the appropriate package for your release of Peachtree Linux. ...
      (Bugtraq)