Описание
Security update for tiff
This update for tiff to version 4.0.9 fixes the following issues:
Security issues fixed:
- CVE-2014-8128: Fix out-of-bounds read with malformed TIFF image in multiple tools (bsc#969783).
- CVE-2015-7554: Fix invalid write in tiffsplit / _TIFFVGetField (bsc#960341).
- CVE-2016-10095: Fix stack-based buffer overflow in _TIFFVGetField (tif_dir.c) (bsc#1017690).
- CVE-2016-5318: Fix stackoverflow in thumbnail (bsc#983436).
- CVE-2017-16232: Fix memory-based DoS in tiff2bw (bsc#1069213).
Список пакетов
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Software Development Kit 12 SP2
SUSE Linux Enterprise Software Development Kit 12 SP3
Ссылки
- Link for SUSE-SU-2018:0073-1
- E-Mail link for SUSE-SU-2018:0073-1
- SUSE Security Ratings
- SUSE Bug 1017690
- SUSE Bug 1069213
- SUSE Bug 960341
- SUSE Bug 969783
- SUSE Bug 983436
- SUSE CVE CVE-2014-8128 page
- SUSE CVE CVE-2015-7554 page
- SUSE CVE CVE-2016-10095 page
- SUSE CVE CVE-2016-5318 page
- SUSE CVE CVE-2017-16232 page
Описание
LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image.
Затронутые продукты
Ссылки
- CVE-2014-8128
- SUSE Bug 1007276
- SUSE Bug 1017690
- SUSE Bug 1040322
- SUSE Bug 1206220
- SUSE Bug 914890
- SUSE Bug 916925
- SUSE Bug 942690
- SUSE Bug 960341
- SUSE Bug 969783
- SUSE Bug 974621
- SUSE Bug 983436
Описание
The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image.
Затронутые продукты
Ссылки
- CVE-2015-7554
- SUSE Bug 1007276
- SUSE Bug 1017690
- SUSE Bug 1040322
- SUSE Bug 960341
- SUSE Bug 974621
- SUSE Bug 983436
Описание
Stack-based buffer overflow in the _TIFFVGetField function in tif_dir.c in LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7 and 4.0.8 allows remote attackers to cause a denial of service (crash) via a crafted TIFF file.
Затронутые продукты
Ссылки
- CVE-2016-10095
- SUSE Bug 1017690
- SUSE Bug 960341
- SUSE Bug 983436
Описание
Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff.
Затронутые продукты
Ссылки
- CVE-2016-5318
- SUSE Bug 1007276
- SUSE Bug 1017690
- SUSE Bug 1040322
- SUSE Bug 960341
- SUSE Bug 974621
- SUSE Bug 983436
Описание
LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue
Затронутые продукты
Ссылки
- CVE-2017-16232
- SUSE Bug 1069213