Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-20801

Опубликовано: 17 нояб. 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-20801: libtiff security update (MODERATE)

[4.4.0-15]

  • backport documentation change for CVE-2023-52355 (RHEL-17328)

[4.4.0-14]

  • fix CVE-2023-52356: libtiff could crash in TIFFReadRGBATileExt when parsing crafted tiff file (RHEL-17337)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

libtiff

4.4.0-15.el9

libtiff-devel

4.4.0-15.el9

libtiff-tools

4.4.0-15.el9

Oracle Linux x86_64

libtiff

4.4.0-15.el9

libtiff-devel

4.4.0-15.el9

libtiff-tools

4.4.0-15.el9

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

CVSS3: 7.5
redhat
около 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

CVSS3: 7.5
nvd
почти 2 года назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

CVSS3: 7.5
debian
почти 2 года назад

An out-of-memory flaw was found in libtiff that could be triggered by ...

CVSS3: 7.5
ubuntu
почти 2 года назад

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.