MGASA-2019-0101
Dashboard / Vulnerabilities / MGASA-2019-0101
Summary: Updated libtiff packages fix security vulnerability
Details: An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900. (CVE-2019-7663) The invertImage() function in tiffcrop.c:9206 allows remote attackers to cause a denial of service (heap buffer overflow) via invert color space.
References: https://advisories.mageia.org/MGASA-2019-0101.html, https://bugs.mageia.org/show_bug.cgi?id=24393, http://bugzilla.maptools.org/show_bug.cgi?id=2831, https://lists.fedoraproject.org/archives/list/[email protected]/thread/QLLVSXFUKP2QSOFI6RRTYD737HBS7UGT/
Affected packages
Package
Name: libtiff
Purl: pkg:rpm/mageia/libtiff?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
