First published: Mon Jun 03 2019(Updated: )
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files. Reference: <a href="https://gitlab.gnome.org/GNOME/evince/issues/1129">https://gitlab.gnome.org/GNOME/evince/issues/1129</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Evince | <=3.32.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability REDHAT-BUG-1716295 is classified as a moderate severity issue due to potential uninitialized memory use.
To fix REDHAT-BUG-1716295, upgrade GNOME Evince to version 3.32.1 or later, which addresses the error handling issue.
REDHAT-BUG-1716295 can lead to application crashes or unexpected behavior when processing certain TIFF image files.
Versions of GNOME Evince up to and including 3.32.0 are affected by REDHAT-BUG-1716295.
The vulnerability REDHAT-BUG-1716295 was reported in the GNOME Bugzilla system.