Описание
Security update for tiff
This update for tiff fixes the following issues:
- CVE-2015-8781, CVE-2015-8782, CVE-2015-8783: Out-of-bounds writes for invalid images (bsc#964225)
- CVE-2016-3186: Buffer overflow in gif2tiff (bnc#973340).
- CVE-2016-5875: heap-based buffer overflow when using the PixarLog compressionformat (bsc#987351)
- CVE-2016-5316: Out-of-bounds read in PixarLogCleanup() function in tif_pixarlog.c (bsc#984837)
- CVE-2016-5314: Out-of-bounds write in PixarLogDecode() function (bsc#984831)
- CVE-2016-5317: Out-of-bounds write in PixarLogDecode() function in libtiff.so (bsc#984842)
- CVE-2016-5320: Out-of-bounds write in PixarLogDecode() function in tif_pixarlog.c (bsc#984808)
Список пакетов
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server for SAP Applications 12 SP1
SUSE Linux Enterprise Software Development Kit 12 SP1
Ссылки
- Link for SUSE-SU-2016:2271-1
- E-Mail link for SUSE-SU-2016:2271-1
- SUSE Security Ratings
- SUSE Bug 964225
- SUSE Bug 973340
- SUSE Bug 984808
- SUSE Bug 984831
- SUSE Bug 984837
- SUSE Bug 984842
- SUSE Bug 987351
- SUSE CVE CVE-2015-8781 page
- SUSE CVE CVE-2015-8782 page
- SUSE CVE CVE-2015-8783 page
- SUSE CVE CVE-2016-3186 page
- SUSE CVE CVE-2016-5314 page
- SUSE CVE CVE-2016-5316 page
- SUSE CVE CVE-2016-5317 page
- SUSE CVE CVE-2016-5320 page
- SUSE CVE CVE-2016-5875 page
Описание
tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of samples per pixel in a LogL compressed TIFF image, a different vulnerability than CVE-2015-8782.
Затронутые продукты
Ссылки
- CVE-2015-8781
- SUSE Bug 964213
- SUSE Bug 964225
Описание
tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a different vulnerability than CVE-2015-8781.
Затронутые продукты
Ссылки
- CVE-2015-8782
- SUSE Bug 964213
- SUSE Bug 964225
Описание
tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.
Затронутые продукты
Ссылки
- CVE-2015-8783
- SUSE Bug 964213
- SUSE Bug 964225
Описание
Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.
Затронутые продукты
Ссылки
- CVE-2016-3186
- SUSE Bug 973340
- SUSE Bug 983268
Описание
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr.
Затронутые продукты
Ссылки
- CVE-2016-5314
- SUSE Bug 984831
- SUSE Bug 987351
Описание
Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by sending a crafted TIFF image to the rgb2ycbcr tool.
Затронутые продукты
Ссылки
- CVE-2016-5316
- SUSE Bug 984837
Описание
Buffer overflow in the PixarLogDecode function in libtiff.so in the PixarLogDecode function in libtiff 4.0.6 and earlier, as used in GNOME nautilus, allows attackers to cause a denial of service attack (crash) via a crafted TIFF file.
Затронутые продукты
Ссылки
- CVE-2016-5317
- SUSE Bug 984842
Описание
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-5314. Reason: This candidate is a reservation duplicate of CVE-2016-5314. Notes: All CVE users should reference CVE-2016-5314 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Затронутые продукты
Ссылки
- CVE-2016-5320
- SUSE Bug 1007284
- SUSE Bug 984808
- SUSE Bug 987351
Описание
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-5314. Reason: This candidate is a reservation duplicate of CVE-2016-5314. Notes: All CVE users should reference CVE-2016-5314 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Затронутые продукты
Ссылки
- CVE-2016-5875
- SUSE Bug 1007284
- SUSE Bug 984809
- SUSE Bug 984831
- SUSE Bug 987351