Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:4259-1

Опубликовано: 28 нояб. 2022
Источник: suse-cvrf

Описание

Security update for tiff

This update for tiff fixes the following issues:

  • CVE-2022-3597: Fixed out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c (bnc#1204641).
  • CVE-2022-3599: Fixed out-of-bounds read in writeSingleSection in tools/tiffcrop.c (bnc#1204643).
  • CVE-2022-3626: Fixed out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c (bnc#1204644)
  • CVE-2022-3627: Fixed out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c (bnc#1204645).
  • CVE-2022-3970: Fixed unsigned integer overflow in TIFFReadRGBATileExt() (bnc#1205392).

Список пакетов

Container suse/nginx:latest
libtiff5-4.0.9-150000.45.19.1
Container suse/rmt-nginx:latest
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP2-SAP-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP2-SAP-BYOS-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP2-SAP-BYOS-EC2-HVM
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP2-SAP-BYOS-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP2-SAP-EC2-HVM
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP2-SAP-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP3-SAP-BYOS-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP3-SAP-BYOS-EC2-HVM
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP3-SAP-BYOS-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP3-SAPCAL-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP3-SAPCAL-EC2-HVM
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP3-SAPCAL-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-Hardened-BYOS
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-Hardened-BYOS-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-Hardened-BYOS-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-Hardened-BYOS-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-Azure-LI-BYOS
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-BYOS
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-BYOS-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-BYOS-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-BYOS-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-Hardened
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-Hardened-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-Hardened-BYOS
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-Hardened-BYOS-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-Hardened-BYOS-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-Hardened-BYOS-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-Hardened-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAP-Hardened-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAPCAL
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAPCAL-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAPCAL-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SAPCAL-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SUSE-Rancher-Setup-BYOS
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP4-SUSE-Rancher-Setup-BYOS-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-Hardened-BYOS-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-Hardened-BYOS-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-Hardened-BYOS-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-Azure-3P
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-Azure-LI-BYOS
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-Azure-LI-BYOS-Production
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-Azure-VLI-BYOS
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-BYOS-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-BYOS-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-BYOS-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-Hardened-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-Hardened-BYOS-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-Hardened-BYOS-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-Hardened-BYOS-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-Hardened-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAP-Hardened-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAPCAL-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAPCAL-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP5-SAPCAL-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-Azure-LI-BYOS
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-Azure-VLI-BYOS
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-Azure-VLI-BYOS-Production
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-BYOS
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-BYOS-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-BYOS-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-BYOS-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-Hardened
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-Hardened-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-Hardened-BYOS
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-Hardened-BYOS-Azure
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-Hardened-BYOS-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-Hardened-BYOS-GCE
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-Hardened-EC2
libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP6-SAP-Hardened-GCE
libtiff5-4.0.9-150000.45.19.1
SUSE Enterprise Storage 6
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Enterprise Storage 7
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise Micro 5.2
libtiff5-4.0.9-150000.45.19.1
SUSE Linux Enterprise Micro 5.3
libtiff5-4.0.9-150000.45.19.1
SUSE Linux Enterprise Module for Basesystem 15 SP3
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
SUSE Linux Enterprise Module for Basesystem 15 SP4
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP3
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise Module for Package Hub 15 SP3
libtiff5-32bit-4.0.9-150000.45.19.1
tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Module for Package Hub 15 SP4
tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server 15 SP1-BCL
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server 15 SP1-LTSS
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server 15 SP2-BCL
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server 15 SP2-LTSS
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server 15-LTSS
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server for SAP Applications 15
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Manager Proxy 4.1
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Manager Retail Branch Server 4.1
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
SUSE Manager Server 4.1
libtiff-devel-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
openSUSE Leap 15.3
libtiff-devel-4.0.9-150000.45.19.1
libtiff-devel-32bit-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
tiff-4.0.9-150000.45.19.1
openSUSE Leap 15.4
libtiff-devel-4.0.9-150000.45.19.1
libtiff-devel-32bit-4.0.9-150000.45.19.1
libtiff5-4.0.9-150000.45.19.1
libtiff5-32bit-4.0.9-150000.45.19.1
tiff-4.0.9-150000.45.19.1
openSUSE Leap Micro 5.2
libtiff5-4.0.9-150000.45.19.1
openSUSE Leap Micro 5.3
libtiff5-4.0.9-150000.45.19.1

Описание

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6826, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.


Затронутые продукты
Container suse/nginx:latest:libtiff5-4.0.9-150000.45.19.1
Container suse/rmt-nginx:latest:libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:libtiff5-4.0.9-150000.45.19.1

Ссылки

Описание

LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.


Затронутые продукты
Container suse/nginx:latest:libtiff5-4.0.9-150000.45.19.1
Container suse/rmt-nginx:latest:libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:libtiff5-4.0.9-150000.45.19.1

Ссылки

Описание

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections, tools/tiffcrop.c:7619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.


Затронутые продукты
Container suse/nginx:latest:libtiff5-4.0.9-150000.45.19.1
Container suse/rmt-nginx:latest:libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:libtiff5-4.0.9-150000.45.19.1

Ссылки

Описание

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6860, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.


Затронутые продукты
Container suse/nginx:latest:libtiff5-4.0.9-150000.45.19.1
Container suse/rmt-nginx:latest:libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:libtiff5-4.0.9-150000.45.19.1

Ссылки

Описание

A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.


Затронутые продукты
Container suse/nginx:latest:libtiff5-4.0.9-150000.45.19.1
Container suse/rmt-nginx:latest:libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libtiff5-4.0.9-150000.45.19.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:libtiff5-4.0.9-150000.45.19.1

Ссылки
Уязвимость SUSE-SU-2022:4259-1