SUSE-SU-2018:3911-2
Dashboard / Vulnerabilities / SUSE-SU-2018:3911-2
SUSE-SU-2018:3911-2
Summary: Security update for tiff
Details: This update for tiff fixes the following issues: Security issues fixed: - CVE-2018-12900: Fixed heap-based buffer overflow in the cpSeparateBufToContigBuf (bsc#1099257). - CVE-2018-18661: Fixed NULL pointer dereference in the function LZWDecode in the file tif_lzw.c (bsc#1113672). - CVE-2018-18557: Fixed JBIG decode can lead to out-of-bounds write (bsc#1113094). Non-security issues fixed: - asan_build: build ASAN included - debug_build: build more suitable for debugging
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183911-2/, https://bugzilla.suse.com/1099257, https://bugzilla.suse.com/1113094, https://bugzilla.suse.com/1113672, https://www.suse.com/security/cve/CVE-2018-12900, https://www.suse.com/security/cve/CVE-2018-18557, https://www.suse.com/security/cve/CVE-2018-18661
Affected packages
Package
Name: tiff
Purl: pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
