SUSE-SU-2022:3679-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3679-1
SUSE-SU-2022:3679-1
Summary: Security update for tiff
Details: This update for tiff fixes the following issues: - CVE-2022-2519: Fixed a double free in rotateImage() (bsc#1202968). - CVE-2022-2520: Fixed a assertion failure in rotateImage() (bsc#1202973). - CVE-2022-2521: Fixed invalid free in TIFFClose() (bsc#1202971). - CVE-2022-2867: Fixed out of bounds read and write in tiffcrop.c (bsc#1202466). - CVE-2022-2868: Fixed out of bounds read in reverseSamples16bits() (bsc#1202467). - CVE-2022-2869: Fixed out of bounds read and write in extractContigSamples8bits() (bsc#1202468). - CVE-2022-34526: Fixed stack overflow in the _TIFFVGetField function of Tiffsplit (bsc#1202026).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223679-1/, https://bugzilla.suse.com/1201723, https://bugzilla.suse.com/1201971, https://bugzilla.suse.com/1202026, https://bugzilla.suse.com/1202466, https://bugzilla.suse.com/1202467, https://bugzilla.suse.com/1202468, https://bugzilla.suse.com/1202968, https://bugzilla.suse.com/1202971, https://bugzilla.suse.com/1202973, https://www.suse.com/security/cve/CVE-2022-0561, https://www.suse.com/security/cve/CVE-2022-2519, https://www.suse.com/security/cve/CVE-2022-2520, https://www.suse.com/security/cve/CVE-2022-2521, https://www.suse.com/security/cve/CVE-2022-2867, https://www.suse.com/security/cve/CVE-2022-2868, https://www.suse.com/security/cve/CVE-2022-2869, https://www.suse.com/security/cve/CVE-2022-34266, https://www.suse.com/security/cve/CVE-2022-34526
Affected packages
Package
Name: tiff
Purl: pkg:rpm/suse/tiff&distro=SUSE%20OpenStack%20Cloud%209
Affected ranges
Type: ECOSYSTEM
Events:
