Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2023:0095

Опубликовано: 12 янв. 2023
Источник: rocky
Оценка: Moderate

Описание

Moderate: libtiff security update

The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.

Security Fix(es):

  • LibTiff: DoS from Divide By Zero Error (CVE-2022-2056, CVE-2022-2057, CVE-2022-2058)

  • libtiff: Double free or corruption in rotateImage() function at tiffcrop.c (CVE-2022-2519)

  • libtiff: uint32_t underflow leads to out of bounds read and write in tiffcrop.c (CVE-2022-2867)

  • libtiff: tiffcrop.c has uint32_t underflow which leads to out of bounds read and write in extractContigSamples8bits() (CVE-2022-2869)

  • libtiff: tiffcrop: heap-buffer-overflow in extractImageSection in tiffcrop.c (CVE-2022-2953)

  • libtiff: Assertion fail in rotateImage() function at tiffcrop.c (CVE-2022-2520)

  • libtiff: Invalid pointer free operation in TIFFClose() at tif_close.c (CVE-2022-2521)

  • libtiff: Invalid crop_width and/or crop_length could cause an out-of-bounds read in reverseSamples16bits() (CVE-2022-2868)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libtiffx86_6426.el8_7libtiff-4.0.9-26.el8_7.x86_64.rpm
libtiff-develx86_6426.el8_7libtiff-devel-4.0.9-26.el8_7.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 2 лет назад

ELSA-2023-0095: libtiff security update (MODERATE)

rocky
больше 2 лет назад

Moderate: libtiff security update

oracle-oval
больше 2 лет назад

ELSA-2023-0302: libtiff security update (MODERATE)

suse-cvrf
около 3 лет назад

Security update for tiff

suse-cvrf
около 3 лет назад

Security update for tiff