Описание
ELSA-2026-41892: libtiff security, bug fix, and enhancement update (IMPORTANT)
[4.6.0-8.4]
- fix CVE-2026-12912: heap-buffer-overflow in PixarLog 8BITABGR decode with stride 3 (RHEL-189374)
- make sure documentation is updated during build for CVE-2023-52355 (RHEL-178281)
[4.6.0-8.3]
- reintroduce ignore option -i as it is required for tests (RHEL-185328)
[4.6.0-8.2]
- backport documentation change for CVE-2023-52355 (RHEL-178281)
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
libtiff
4.6.0-8.el10_2.4
libtiff-devel
4.6.0-8.el10_2.4
libtiff-tools
4.6.0-8.el10_2.4
Oracle Linux x86_64
libtiff
4.6.0-8.el10_2.4
libtiff-devel
4.6.0-8.el10_2.4
libtiff-tools
4.6.0-8.el10_2.4
Связанные CVE
Связанные уязвимости
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
Libtiff: tiffrasterscanlinesize64 produce too-big size and could cause oom