Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:47183

Опубликовано: 03 авг. 2026
Источник: rocky
Оценка: Important

Описание

Important: compat-libtiff3 security update

The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff.

Security Fix(es):

  • libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
compat-libtiff3aarch6416.el8_10compat-libtiff3-3.9.4-16.el8_10.aarch64.rpm
compat-libtiff3i68616.el8_10compat-libtiff3-3.9.4-16.el8_10.i686.rpm
compat-libtiff3x86_6416.el8_10compat-libtiff3-3.9.4-16.el8_10.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.3
ubuntu
3 месяца назад

A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).

CVSS3: 7.3
redhat
5 месяцев назад

A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).

CVSS3: 7.3
nvd
3 месяца назад

A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).

CVSS3: 7.3
msrc
2 месяца назад

Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image

CVSS3: 7.3
debian
3 месяца назад

A flaw was found in libtiff. A remote attacker could exploit this vuln ...