[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256488

 
 

909

 
 

199193

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2023:3711-01 -- Redhat libtiff

ID: oval:org.secpod.oval:def:507818Date: (C)2023-07-05   (M)2024-03-28
Class: PATCHFamily: unix




The libtiff packages contain a library of functions for manipulating Tagged Image File Format files. Security Fix: * libtiff: heap-based buffer overflow in processCropSelections in tools/tiffcrop.c * libtiff: out-of-bounds read in extractContigSamplesShifted16bits in tools/tiffcrop.c * libtiff: out-of-bounds read in extractContigSamplesShifted24bits in tools/tiffcrop.c * libtiff: out-of-bounds read in _TIFFmemcpy in libtiff/tif_unix.c when called by functions in tools/tiffcrop.c * libtiff: out-of-bounds read in extractContigSamplesShifted8bits in tools/tiffcrop.c * libtiff: use-after-free in extractContigSamplesShifted32bits in tools/tiffcrop.c * libtiff: out-of-bounds write in extractContigSamplesShifted16bits in tools/tiffcrop.c * libtiff: out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c when called by functions in tools/tiffcrop.c * libtiff: out-of-bounds write in extractContigSamplesShifted32bits in tools/tiffcrop.c * libtiff: out-of-bounds write in extractContigSamplesShifted16bits in tools/tiffcrop.c * libtiff: out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.

Platform:
Red Hat Enterprise Linux 9
Product:
libtiff
Reference:
RHSA-2023:3711-01
CVE-2022-48281
CVE-2023-0795
CVE-2023-0796
CVE-2023-0797
CVE-2023-0798
CVE-2023-0799
CVE-2023-0800
CVE-2023-0801
CVE-2023-0802
CVE-2023-0803
CVE-2023-0804
CVE    11
CVE-2023-0799
CVE-2023-0800
CVE-2023-0797
CVE-2023-0798
...

© SecPod Technologies