Bug 611890 (CVE-2010-2631)

Summary: CVE-2010-2631 libtiff: unknown tag handling assertion failure
Product: [Other] Security Response Reporter: Tomas Hoger <thoger>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: fweimer, tgl
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2010-07-06 19:18:54 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 603699, 1148869, 1148870    
Bug Blocks:    

Description Tomas Hoger 2010-07-06 19:08:30 UTC
LibTIFF 3.9.0 ignores tags in certain situations during the first
stage of TIFF file processing and does not properly handle this during
the second stage, which allows remote attackers to cause a denial of
service (application crash) via a crafted file, a different
vulnerability than CVE-2010-2481.

References:
http://bugzilla.maptools.org/show_bug.cgi?id=2210

Comment 1 Tomas Hoger 2010-07-06 19:18:54 UTC
It seems this CVE was assigned based on the following comment in the upstream bug report:
  http://bugzilla.maptools.org/show_bug.cgi?id=2210#c3

It was added in response to the Red Hat bug:
  https://bugzilla.redhat.com/show_bug.cgi?id=603699

Upstream bug report #2210 contains patch to address issues related to handling of unknown tags, which could lead to various libtiff crashes, which got CVEs assigned (CVE-2010-2481, CVE-2010-2630 and CVE-2010-2631).  This particular vector did not affect libtiff packages in Red Hat Enterprise Linux 3, 4 and 5 (see bug #603699, comment #0).  Patch is included in libtiff-3.9.4-1 Fedora packages.

Statement:

Not vulnerable. This issue did not affect the versions of libtiff as shipped with Red Hat Enterprise Linux 3, 4, or 5.