SUSE-SU-2022:0480-1 -- SLES tiff, libtiff-devel, libtiff5ID: oval:org.secpod.oval:def:89047629 | Date: (C)2022-11-04 (M)2023-08-16 |
Class: PATCH | Family: unix |
This update for tiff fixes the following issues: - CVE-2017-17095: Fixed DoS in tools/pal2rgb.c in pal2rgb . - CVE-2019-17546: Fixed integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image . - CVE-2020-19131: Fixed buffer overflow in tiffcrop that may cause DoS via the invertImage function . - CVE-2020-35521: Fixed memory allocation failure in tif_read.c . - CVE-2020-35522: Fixed memory allocation failure in tif_pixarlog.c . - CVE-2020-35523: Fixed integer overflow in tif_getimage.c . - CVE-2020-35524: Fixed heap-based buffer overflow in TIFF2PDF tool . - CVE-2022-22844: Fixed out-of-bounds read in _TIFFmemcpy in tif_unix.c .
Platform: |
SUSE Linux Enterprise Desktop 15 SP4 |
SUSE Linux Enterprise Server 15 SP4 |
SUSE Linux Enterprise Server 15 SP3 |
SUSE Linux Enterprise Desktop 15 SP3 |
Product: |
tiff |
libtiff-devel |
libtiff5 |