SUSE-SU-2018:2676-1 -- SLES tiff, libtiffID: oval:org.secpod.oval:def:89002397 | Date: (C)2021-02-26 (M)2023-12-26 |
Class: PATCH | Family: unix |
This update for tiff fixes the following issues: The following security vulnerabilities were addressed: - CVE-2015-8668: Fixed a heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff, which allowed remote attackers to execute arbitrary code or cause a denial of service via a large width field in a specially crafted BMP image. - CVE-2018-10779: Fixed a heap-based buffer over-read in TIFFWriteScanline in tif_write.c - CVE-2017-17942: Fixed a heap-based buffer overflow in the function PackBitsEncode in tif_packbits.c. - CVE-2016-5319: Fixed a beap-based buffer overflow in bmp2tiff
Platform: |
SUSE Linux Enterprise Server 11 SP4 |