SUSE-SU-2022:1667-1
Dashboard / Vulnerabilities / SUSE-SU-2022:1667-1
SUSE-SU-2022:1667-1
Summary: Security update for tiff
Details: This update for tiff fixes the following issues: - CVE-2022-0561: Fixed null source pointer passed as an argument to memcpy() within TIFFFetchStripThing() in tif_dirread.c (bsc#1195964). - CVE-2022-0562: Fixed null source pointer passed as an argument to memcpy() within TIFFReadDirectory() in tif_dirread.c (bsc#1195965). - CVE-2022-0865: Fixed assertion failure in TIFFReadAndRealloc (bsc#1197066). - CVE-2022-0909: Fixed divide by zero error in tiffcrop that could have led to a denial-of-service via a crafted tiff file (bsc#1197072). - CVE-2022-0924: Fixed out-of-bounds read error in tiffcp that could have led to a denial-of-service via a crafted tiff file (bsc#1197073). - CVE-2022-0908: Fixed null source pointer passed as an argument to memcpy in TIFFFetchNormalTag() (bsc#1197074). - CVE-2022-1056: Fixed out-of-bounds read error in tiffcrop that could have led to a denial-of-service via a crafted tiff file (bsc#1197631). - CVE-2022-0891: Fixed heap buffer overflow in extractImageSection (bsc#1197068).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20221667-1/, https://bugzilla.suse.com/1195964, https://bugzilla.suse.com/1195965, https://bugzilla.suse.com/1197066, https://bugzilla.suse.com/1197068, https://bugzilla.suse.com/1197072, https://bugzilla.suse.com/1197073, https://bugzilla.suse.com/1197074, https://bugzilla.suse.com/1197631, https://www.suse.com/security/cve/CVE-2022-0561, https://www.suse.com/security/cve/CVE-2022-0562, https://www.suse.com/security/cve/CVE-2022-0865, https://www.suse.com/security/cve/CVE-2022-0891, https://www.suse.com/security/cve/CVE-2022-0908, https://www.suse.com/security/cve/CVE-2022-0909, https://www.suse.com/security/cve/CVE-2022-0924, https://www.suse.com/security/cve/CVE-2022-1056
Affected packages
Package
Name: tiff
Purl: pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
