SUSE-SU-2024:0915-1
Dashboard / Vulnerabilities / SUSE-SU-2024:0915-1
SUSE-SU-2024:0915-1
Summary: Security update for tiff
Details: This update for tiff fixes the following issues: - CVE-2023-41175: Fixed potential integer overflow in raw2tiff.c (bsc#1214686). - CVE-2023-38288: Fixed potential integer overflow in raw2tiff.c (bsc#1213590). - CVE-2023-40745: Fixed integer overflow in tiffcp.c (bsc#1214687). - CVE-2015-8668: Fixed Heap-based buffer overflow in bmp2tiff / PackBitsEncode (bsc#960589).
References: https://www.suse.com/support/update/announcement/2024/suse-su-20240915-1/, https://bugzilla.suse.com/1213590, https://bugzilla.suse.com/1214686, https://bugzilla.suse.com/1214687, https://bugzilla.suse.com/1221187, https://bugzilla.suse.com/960589, https://www.suse.com/security/cve/CVE-2015-8668, https://www.suse.com/security/cve/CVE-2023-38288, https://www.suse.com/security/cve/CVE-2023-40745, https://www.suse.com/security/cve/CVE-2023-41175
Affected packages
Package
Name: tiff
Purl: pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
