Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:1472-1

Опубликовано: 30 мая 2018
Источник: suse-cvrf

Описание

Security update for tiff

This update for tiff fixes the following issues:

Security issues fixed:

  • CVE-2016-5315: The setByteArray function in tif_dir.c allowed remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image. (bsc#984809)
  • CVE-2016-10267: LibTIFF allowed remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_ojpeg.c:816:8. (bsc#1017694)
  • CVE-2016-10269: LibTIFF allowed remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to 'READ of size 512' and libtiff/tif_unix.c:340:2. (bsc#1031254)
  • CVE-2016-10270: LibTIFF allowed remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to 'READ of size 8' and libtiff/tif_read.c:523:22. (bsc#1031250)
  • CVE-2017-18013: In LibTIFF, there was a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash. (bsc#1074317)
  • CVE-2017-7593: tif_read.c did not ensure that tif_rawdata is properly initialized, which might have allowed remote attackers to obtain sensitive information from process memory via a crafted image. (bsc#1033129)
  • CVE-2017-7595: The JPEGSetupEncode function in tiff_jpeg.c allowed remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image. (bsc#1033127)
  • CVE-2017-7596: LibTIFF had an 'outside the range of representable values of type float' undefined behavior issue, which might have allowed remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. (bsc#1033126)
  • CVE-2017-7597: tif_dirread.c had an 'outside the range of representable values of type float' undefined behavior issue, which might have allowed remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. (bsc#1033120)
  • CVE-2017-7599: LibTIFF had an 'outside the range of representable values of type short' undefined behavior issue, which might have allowed remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. (bsc#1033113)
  • CVE-2017-7600: LibTIFF had an 'outside the range of representable values of type unsigned char' undefined behavior issue, which might have allowed remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. (bsc#1033112)
  • CVE-2017-7601: LibTIFF had a 'shift exponent too large for 64-bit type long' undefined behavior issue, which might have allowed remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. (bsc#1033111)
  • CVE-2017-7602: LibTIFF had a signed integer overflow, which might have allowed remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. (bsc#1033109)
  • Multiple divide by zero issues
  • CVE-2016-5314: Buffer overflow in the PixarLogDecode function in tif_pixarlog.c allowed remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr. (bsc#987351 bsc#984808 bsc#984831)

Список пакетов

SUSE Linux Enterprise Server 11 SP4
libtiff3-3.8.2-141.169.6.1
libtiff3-32bit-3.8.2-141.169.6.1
libtiff3-x86-3.8.2-141.169.6.1
tiff-3.8.2-141.169.6.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
libtiff3-3.8.2-141.169.6.1
libtiff3-32bit-3.8.2-141.169.6.1
libtiff3-x86-3.8.2-141.169.6.1
tiff-3.8.2-141.169.6.1
SUSE Linux Enterprise Software Development Kit 11 SP4
libtiff-devel-3.8.2-141.169.6.1
libtiff-devel-32bit-3.8.2-141.169.6.1

Описание

LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_ojpeg.c:816:8.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки

Описание

LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6 and 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 512" and libtiff/tif_unix.c:340:2.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки

Описание

LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 8" and libtiff/tif_read.c:523:22.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки

Описание

Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки

Описание

The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки

Описание

In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки

Описание

tif_read.c in LibTIFF 4.0.7 does not ensure that tif_rawdata is properly initialized, which might allow remote attackers to obtain sensitive information from process memory via a crafted image.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки

Описание

The JPEGSetupEncode function in tiff_jpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки

Описание

LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки

Описание

tif_dirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки

Описание

LibTIFF 4.0.7 has an "outside the range of representable values of type short" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки

Описание

LibTIFF 4.0.7 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки

Описание

LibTIFF 4.0.7 has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки

Описание

LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libtiff3-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-32bit-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:libtiff3-x86-3.8.2-141.169.6.1
SUSE Linux Enterprise Server 11 SP4:tiff-3.8.2-141.169.6.1

Ссылки
Уязвимость SUSE-SU-2018:1472-1