Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2023:5353

Опубликовано: 05 окт. 2023
Источник: rocky
Оценка: Moderate

Описание

Moderate: libtiff security update

The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.

Security Fix(es):

  • libtiff: out-of-bounds write in extractContigSamplesShifted16bits() in tools/tiffcrop.c (CVE-2023-0800)

  • libtiff: out-of-bounds write in _TIFFmemcpy() in libtiff/tif_unix.c when called by functions in tools/tiffcrop.c (CVE-2023-0801)

  • libtiff: out-of-bounds write in extractContigSamplesShifted32bits() in tools/tiffcrop.c (CVE-2023-0802)

  • libtiff: out-of-bounds write in extractContigSamplesShifted16bits() in tools/tiffcrop.c (CVE-2023-0803)

  • libtiff: out-of-bounds write in extractContigSamplesShifted24bits() in tools/tiffcrop.c (CVE-2023-0804)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libtiffx86_6429.el8_8libtiff-4.0.9-29.el8_8.x86_64.rpm
libtiff-develx86_6429.el8_8libtiff-devel-4.0.9-29.el8_8.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 1 года назад

ELSA-2023-5353: libtiff security update (MODERATE)

suse-cvrf
около 2 лет назад

Security update for tiff

suse-cvrf
около 2 лет назад

Security update for tiff

rocky
почти 2 года назад

Moderate: libtiff security update

oracle-oval
около 2 лет назад

ELSA-2023-3711: libtiff security update (MODERATE)