CVE-2009-3296

Publication date 20 October 2009

Last updated 24 July 2024


Ubuntu priority

Multiple integer overflows in tiffread.c in CamlImages 2.2 might allow remote attackers to execute arbitrary code via TIFF images containing large width and height values that trigger heap-based buffer overflows.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
advi 10.10 maverick
Not affected
10.04 LTS lucid
Not affected
9.10 karmic
Fixed 1.6.0-14ubuntu0.1
9.04 jaunty
Fixed 1.6.0-13+lenny2build0.9.04.1
8.10 intrepid Ignored end of life, was needed
8.04 LTS hardy
Fixed 1.6.0-13ubuntu0.1
6.06 LTS dapper Ignored end of life
camlimages 10.10 maverick
Not affected
10.04 LTS lucid
Not affected
9.10 karmic
Fixed 1:3.0.1-3ubuntu0.1
9.04 jaunty
Fixed 1:2.2.0-4+lenny3build0.9.04.1
8.10 intrepid
Fixed 1:2.2.0-3ubuntu0.1
8.04 LTS hardy
Fixed 1:2.2.0-2ubuntu2.1
6.06 LTS dapper Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
camlimages