ALSA-2023:0302
Dashboard / Vulnerabilities / ALSA-2023:0302
ALSA-2023:0302
Summary: Moderate: libtiff security update
Details: The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Security Fix(es): * LibTiff: DoS from Divide By Zero Error (CVE-2022-2056, CVE-2022-2057, CVE-2022-2058) * libtiff: Double free or corruption in rotateImage() function at tiffcrop.c (CVE-2022-2519) * libtiff: tiffcrop: heap-buffer-overflow in extractImageSection in tiffcrop.c (CVE-2022-2953) * libtiff: Assertion fail in rotateImage() function at tiffcrop.c (CVE-2022-2520) * libtiff: Invalid pointer free operation in TIFFClose() at tif_close.c (CVE-2022-2521) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2023:0302, https://access.redhat.com/security/cve/CVE-2022-2056, https://access.redhat.com/security/cve/CVE-2022-2057, https://access.redhat.com/security/cve/CVE-2022-2058, https://access.redhat.com/security/cve/CVE-2022-2519, https://access.redhat.com/security/cve/CVE-2022-2520, https://access.redhat.com/security/cve/CVE-2022-2521, https://access.redhat.com/security/cve/CVE-2022-2953, https://bugzilla.redhat.com/2103222, https://bugzilla.redhat.com/2122789, https://bugzilla.redhat.com/2122792, https://bugzilla.redhat.com/2122799, https://bugzilla.redhat.com/2134432, https://errata.almalinux.org/9/ALSA-2023-0302.html
Affected packages
Package
Name: libtiff
Purl: pkg:rpm/almalinux/libtiff
Affected ranges
Type: ECOSYSTEM
Events:
