Описание
Security update for tiff
This update for tiff fixes the following issues:
- CVE-2015-8781, CVE-2015-8782, CVE-2015-8783: Out-of-bounds writes for invalid images (bsc#964225)
- CVE-2015-7554: Out-of-bounds Write in the thumbnail and tiffcmp tools (bsc#960341)
Список пакетов
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise Server 11 SP4
SUSE Linux Enterprise Server for SAP Applications 11 SP4
SUSE Linux Enterprise Software Development Kit 11 SP4
Ссылки
- Link for SUSE-SU-2016:0353-1
- E-Mail link for SUSE-SU-2016:0353-1
- SUSE Security Ratings
- SUSE Bug 960341
- SUSE Bug 964225
- SUSE CVE CVE-2015-7554 page
- SUSE CVE CVE-2015-8781 page
- SUSE CVE CVE-2015-8782 page
- SUSE CVE CVE-2015-8783 page
Описание
The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image.
Затронутые продукты
Ссылки
- CVE-2015-7554
- SUSE Bug 1007276
- SUSE Bug 1017690
- SUSE Bug 1040322
- SUSE Bug 960341
- SUSE Bug 974621
- SUSE Bug 983436
Описание
tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of samples per pixel in a LogL compressed TIFF image, a different vulnerability than CVE-2015-8782.
Затронутые продукты
Ссылки
- CVE-2015-8781
- SUSE Bug 964213
- SUSE Bug 964225
Описание
tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a different vulnerability than CVE-2015-8781.
Затронутые продукты
Ссылки
- CVE-2015-8782
- SUSE Bug 964213
- SUSE Bug 964225
Описание
tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.
Затронутые продукты
Ссылки
- CVE-2015-8783
- SUSE Bug 964213
- SUSE Bug 964225