Описание
Security update for tiff
This update for tiff fixes the following issues
- CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog-compressed TIFF image (bsc#1269779).
- CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434).
Список пакетов
SUSE Linux Enterprise Server 12 SP5-LTSS
libtiff-devel-4.0.9-44.115.1
libtiff5-4.0.9-44.115.1
libtiff5-32bit-4.0.9-44.115.1
tiff-4.0.9-44.115.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libtiff-devel-4.0.9-44.115.1
libtiff5-4.0.9-44.115.1
libtiff5-32bit-4.0.9-44.115.1
tiff-4.0.9-44.115.1
Ссылки
- Link for SUSE-SU-2026:3027-1
- E-Mail link for SUSE-SU-2026:3027-1
- SUSE Security Ratings
- SUSE Bug 1268434
- SUSE Bug 1269779
- SUSE CVE CVE-2026-12912 page
- SUSE CVE CVE-2026-36849 page
Описание
A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:libtiff-devel-4.0.9-44.115.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libtiff5-32bit-4.0.9-44.115.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libtiff5-4.0.9-44.115.1
SUSE Linux Enterprise Server 12 SP5-LTSS:tiff-4.0.9-44.115.1
Ссылки
- CVE-2026-12912
- SUSE Bug 1269779
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:libtiff-devel-4.0.9-44.115.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libtiff5-32bit-4.0.9-44.115.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libtiff5-4.0.9-44.115.1
SUSE Linux Enterprise Server 12 SP5-LTSS:tiff-4.0.9-44.115.1
Ссылки
- CVE-2026-36849
- SUSE Bug 1268434