OracleVM 2.1 : libtiff (OVMSA-2009-0027)

High Nessus Plugin ID 79467


The remote OracleVM host is missing one or more security updates.


The remote OracleVM system is missing necessary patches to address critical security updates :

- Fix buffer overrun risks caused by unchecked integer overflow (CVE-2009-2347) Resolves: #507725

- Fix some more LZW decoding vulnerabilities (CVE-2009-2285) Resolves: #507725

- Update upstream URL

- Use -fno-strict-aliasing per rpmdiff recommendation

- Fix LZW decoding vulnerabilities (CVE-2008-2327) Resolves: #458812

- Remove sgi2tiff.1 and tiffsv.1, since they are for programs we don't ship Resolves: #460120


Update the affected libtiff / libtiff-devel packages.

See Also

Plugin Details

Severity: High

ID: 79467

File Name: oraclevm_OVMSA-2009-0027.nasl

Version: $Revision: 1.6 $

Type: local

Published: 2014/11/26

Modified: 2017/08/15

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:libtiff, p-cpe:/a:oracle:vm:libtiff-devel, cpe:/o:oracle:vm_server:2.1

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2009/10/19

Reference Information

CVE: CVE-2008-2327, CVE-2009-2285, CVE-2009-2347

BID: 30832, 35451, 35652

OSVDB: 55265, 55821, 55822

CWE: 119, 189