Описание
Security update for tiff
This update for tiff fixes the following issues:
- CVE-2019-14973: Fixed an improper check which was depended on the compiler which could have led to integer overflow (bsc#1146608).
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.1
libtiff-devel-4.0.9-lp151.10.3.1
libtiff-devel-32bit-4.0.9-lp151.10.3.1
libtiff5-4.0.9-lp151.10.3.1
libtiff5-32bit-4.0.9-lp151.10.3.1
tiff-4.0.9-lp151.10.3.1
Ссылки
- E-Mail link for openSUSE-SU-2020:1840-1
- SUSE Security Ratings
- SUSE Bug 1146608
- SUSE CVE CVE-2019-14973 page
Описание
_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application crash.
Затронутые продукты
openSUSE Leap 15.1:libtiff-devel-32bit-4.0.9-lp151.10.3.1
openSUSE Leap 15.1:libtiff-devel-4.0.9-lp151.10.3.1
openSUSE Leap 15.1:libtiff5-32bit-4.0.9-lp151.10.3.1
openSUSE Leap 15.1:libtiff5-4.0.9-lp151.10.3.1
Ссылки
- CVE-2019-14973
- SUSE Bug 1146608