Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2023:0302

Опубликовано: 23 янв. 2023
Источник: rocky
Оценка: Moderate

Описание

Moderate: libtiff security update

The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.

Security Fix(es):

  • LibTiff: DoS from Divide By Zero Error (CVE-2022-2056, CVE-2022-2057, CVE-2022-2058)

  • libtiff: Double free or corruption in rotateImage() function at tiffcrop.c (CVE-2022-2519)

  • libtiff: tiffcrop: heap-buffer-overflow in extractImageSection in tiffcrop.c (CVE-2022-2953)

  • libtiff: Assertion fail in rotateImage() function at tiffcrop.c (CVE-2022-2520)

  • libtiff: Invalid pointer free operation in TIFFClose() at tif_close.c (CVE-2022-2521)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
libtiffx86_645.el9_1libtiff-4.4.0-5.el9_1.x86_64.rpm
libtiff-develx86_645.el9_1libtiff-devel-4.4.0-5.el9_1.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 2 лет назад

ELSA-2023-0302: libtiff security update (MODERATE)

rocky
больше 2 лет назад

Moderate: libtiff security update

oracle-oval
больше 2 лет назад

ELSA-2023-0095: libtiff security update (MODERATE)

suse-cvrf
около 3 лет назад

Security update for tiff

suse-cvrf
около 3 лет назад

Security update for tiff