漏洞类别:Amazon Linux漏洞等级:
漏洞信息
Multiple flaws have been discovered in libtiff. A remote attacker could exploit these flaws to cause a crash or memory corruption and, possibly, execute arbitrary code by tricking an application linked against libtiff into processing specially crafted files. (CVE-2014-9655 , CVE-2015-1547 , CVE-2015-8784 , CVE-2015-8683 , CVE-2015-8665 , CVE-2015-8781 , CVE-2015-8782 ,CVE-2015-8783 , CVE-2016-3990 , CVE-2016-5320 )
漏洞危害
Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.
解决方案
Please refer to Amazon advisory ALAS-2016-734 for affected packages and patching details, or update with your package manager.
Patch:
Following are links for downloading patches to fix the vulnerabilities:
ALAS-2016-734: Amazon Linux (compat-libtiff3 (3.9.4-18.14.amzn1) on i686)
ALAS-2016-734: Amazon Linux (compat-libtiff3 (3.9.4-18.14.amzn1) on x86_64)
ALAS-2016-734: Amazon Linux (compat-libtiff3 (3.9.4-18.14.amzn1) on src)
0day
文章评论