MGASA-2016-0017
Dashboard / Vulnerabilities / MGASA-2016-0017
MGASA-2016-0017
Summary: Updated libtiff package fixes security vulnerabilities
Details: In libtiff, in tif_next.c, a potential out-of-bound write in NeXTDecode() triggered by the test case for CVE-2015-1547 (maptools bugzilla #2508). In libtiff, in tif_getimage.c, out-of-bound reads in the TIFFRGBAImage interface in case of unsupported values of SamplesPerPixel/ExtraSamples for LogLUV / CIELab (CVE-2015-8665, CVE-2015-8683).
References: https://advisories.mageia.org/MGASA-2016-0017.html, https://bugs.mageia.org/show_bug.cgi?id=15519, http://bugzilla.maptools.org/show_bug.cgi?id=2508, http://openwall.com/lists/oss-security/2015/12/24/4, http://openwall.com/lists/oss-security/2015/12/26/1
Affected packages
Package
Name: libtiff
Purl: pkg:rpm/mageia/libtiff?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
