ALSA-2022:7585
Dashboard / Vulnerabilities / ALSA-2022:7585
ALSA-2022:7585
Summary: Moderate: libtiff security update
Details: The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Security Fix(es): * libtiff: Denial of Service via crafted TIFF file (CVE-2022-0561) * libtiff: Null source pointer lead to Denial of Service via crafted TIFF file (CVE-2022-0562) * libtiff: reachable assertion (CVE-2022-0865) * libtiff: Out-of-bounds Read error in tiffcp (CVE-2022-0924) * libtiff: stack-buffer-overflow in tiffcp.c in main() (CVE-2022-1355) * libtiff: out-of-bounds read in _TIFFmemcpy() in tif_unix.c (CVE-2022-22844) * libtiff: heap buffer overflow in extractImageSection (CVE-2022-0891) * tiff: Null source pointer passed as an argument to memcpy in TIFFFetchNormalTag() in tif_dirread.c (CVE-2022-0908) * tiff: Divide By Zero error in tiffcrop (CVE-2022-0909) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
References: https://access.redhat.com/errata/RHSA-2022:7585, https://access.redhat.com/security/cve/CVE-2022-0561, https://access.redhat.com/security/cve/CVE-2022-0562, https://access.redhat.com/security/cve/CVE-2022-0865, https://access.redhat.com/security/cve/CVE-2022-0891, https://access.redhat.com/security/cve/CVE-2022-0908, https://access.redhat.com/security/cve/CVE-2022-0909, https://access.redhat.com/security/cve/CVE-2022-0924, https://access.redhat.com/security/cve/CVE-2022-1355, https://access.redhat.com/security/cve/CVE-2022-22844, https://bugzilla.redhat.com/2042603, https://bugzilla.redhat.com/2054494, https://bugzilla.redhat.com/2054495, https://bugzilla.redhat.com/2064145, https://bugzilla.redhat.com/2064146, https://bugzilla.redhat.com/2064148, https://bugzilla.redhat.com/2064406, https://bugzilla.redhat.com/2064411, https://bugzilla.redhat.com/2074415, https://errata.almalinux.org/8/ALSA-2022-7585.html
Affected packages
Package
Name: libtiff
Purl: pkg:rpm/almalinux/libtiff
Affected ranges
Type: ECOSYSTEM
Events:
