gpp_maybe
Security update for tiff
SUSE-SLE-Module-Desktop-Applications-15-SP3-2022-480
This update for tiff fixes the following issues: - CVE-2017-17095: Fixed DoS in tools/pal2rgb.c in pal2rgb (bsc#1071031). - CVE-2019-17546: Fixed integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image (bsc#1154365). - CVE-2020-19131: Fixed buffer overflow in tiffcrop that may cause DoS via the invertImage() function (bsc#1190312). - CVE-2020-35521: Fixed memory allocation failure in tif_read.c (bsc#1182808). - CVE-2020-35522: Fixed memory allocation failure in tif_pixarlog.c (bsc#1182809). - CVE-2020-35523: Fixed integer overflow in tif_getimage.c (bsc#1182811). - CVE-2020-35524: Fixed heap-based buffer overflow in TIFF2PDF tool (bsc#1182812). - CVE-2022-22844: Fixed out-of-bounds read in _TIFFmemcpy in tif_unix.c (bsc#1194539).
-
Release DateFeb 17 2022
-
ReferencesBugzilla: 1071031, 1154365, 1182808, 1182809, 1182811, 1182812, 1190312, 1194539
CVEs: CVE-2017-17095, CVE-2019-17546, CVE-2020-19131, CVE-2020-35521, CVE-2020-35522, CVE-2020-35523, CVE-2020-35524, CVE-2022-22844 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Desktop Applications Module 15.3 x86_64
-
Packageslibtiff5-32bit
The Tiff Library (with JPEG and compression support)tiff4.0.9-45.5.1 lock rpm
Tools for Converting from and to the Tagged Image File Format4.0.9-45.5.1 lock src