SUSE-SU-2016:2271-1
Dashboard / Vulnerabilities / SUSE-SU-2016:2271-1
SUSE-SU-2016:2271-1
Summary: Security update for tiff
Details: This update for tiff fixes the following issues: * CVE-2015-8781, CVE-2015-8782, CVE-2015-8783: Out-of-bounds writes for invalid images (bsc#964225) * CVE-2016-3186: Buffer overflow in gif2tiff (bnc#973340). * CVE-2016-5875: heap-based buffer overflow when using the PixarLog compressionformat (bsc#987351) * CVE-2016-5316: Out-of-bounds read in PixarLogCleanup() function in tif_pixarlog.c (bsc#984837) * CVE-2016-5314: Out-of-bounds write in PixarLogDecode() function (bsc#984831) * CVE-2016-5317: Out-of-bounds write in PixarLogDecode() function in libtiff.so (bsc#984842) * CVE-2016-5320: Out-of-bounds write in PixarLogDecode() function in tif_pixarlog.c (bsc#984808)
References: https://www.suse.com/support/update/announcement/2016/suse-su-20162271-1/, https://bugzilla.suse.com/964225, https://bugzilla.suse.com/973340, https://bugzilla.suse.com/984808, https://bugzilla.suse.com/984831, https://bugzilla.suse.com/984837, https://bugzilla.suse.com/984842, https://bugzilla.suse.com/987351, https://www.suse.com/security/cve/CVE-2015-8781, https://www.suse.com/security/cve/CVE-2015-8782, https://www.suse.com/security/cve/CVE-2015-8783, https://www.suse.com/security/cve/CVE-2016-3186, https://www.suse.com/security/cve/CVE-2016-5314, https://www.suse.com/security/cve/CVE-2016-5316, https://www.suse.com/security/cve/CVE-2016-5317, https://www.suse.com/security/cve/CVE-2016-5320, https://www.suse.com/security/cve/CVE-2016-5875
Affected packages
Package
Name: tiff
Purl: pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
