[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2023:2340-01 -- Redhat libtiff

ID: oval:org.secpod.oval:def:507649Date: (C)2023-05-22   (M)2024-04-29
Class: PATCHFamily: unix




The libtiff packages contain a library of functions for manipulating Tagged Image File Format files. Security Fix: * libtiff: heap Buffer overflows in tiffcrop.c * libtiff: out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix * libtiff: out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c * libtiff: out-of-bounds read in writeSingleSection in tools/tiffcrop.c * libtiff: out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c * libtiff: out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c * libtiff: integer overflow in function TIFFReadRGBATileExt of the file * libtiff: out-of-bounds read in tiffcp in tools/tiffcp.c * libtiff: heap buffer overflow issues related to TIFFTAG_INKNAMES and related TIFFTAG_NUMBEROFINKS value * libtiff: Heap buffer overflow in extractContigSamples32bits, tiffcrop.c For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.2 Release Notes linked from the References section.

Platform:
Red Hat Enterprise Linux 9
Product:
libtiff
Reference:
RHSA-2023:2340-01
CVE-2022-3570
CVE-2022-3597
CVE-2022-3598
CVE-2022-3599
CVE-2022-3626
CVE-2022-3627
CVE-2022-3970
CVE-2022-4645
CVE-2023-30774
CVE-2023-30775
CVE    10
CVE-2022-3598
CVE-2022-3970
CVE-2022-3626
CVE-2022-4645
...
CPE    2
cpe:/a:libtiff:libtiff
cpe:/o:redhat:enterprise_linux:9

© SecPod Technologies