First published: Tue Nov 09 2021(Updated: )
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.<br>Security Fix(es):<br><li> libtiff: Integer overflow in tif_getimage.c (CVE-2020-35523)</li> <li> libtiff: Heap-based buffer overflow in TIFF2PDF tool (CVE-2020-35524)</li> <li> libtiff: Memory allocation failure in tiff2rgba (CVE-2020-35521)</li> <li> libtiff: Memory allocation failure in tiff2rgba (CVE-2020-35522)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libtiff | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-debuginfo | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-debuginfo | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-debugsource | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-debugsource | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-devel | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-devel | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-tools-debuginfo | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-tools-debuginfo | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-debuginfo | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-debugsource | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-devel | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-tools-debuginfo | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff | <4.0.9-20.el8.aa | 4.0.9-20.el8.aa |
redhat/libtiff-debuginfo | <4.0.9-20.el8.aa | 4.0.9-20.el8.aa |
redhat/libtiff-debugsource | <4.0.9-20.el8.aa | 4.0.9-20.el8.aa |
redhat/libtiff-devel | <4.0.9-20.el8.aa | 4.0.9-20.el8.aa |
redhat/libtiff-tools-debuginfo | <4.0.9-20.el8.aa | 4.0.9-20.el8.aa |
redhat/libtiff-tools | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-tools | <4.0.9-20.el8.aa | 4.0.9-20.el8.aa |
redhat/libtiff-tools | <4.0.9-20.el8 | 4.0.9-20.el8 |
redhat/libtiff-tools | <4.0.9-20.el8 | 4.0.9-20.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2021:4241 addresses critical vulnerabilities that could lead to potential denial of service and code execution.
To fix RHSA-2021:4241, update the libtiff packages to version 4.0.9-20.el8 or higher.
RHSA-2021:4241 fixes an integer overflow in tif_getimage.c (CVE-2020-35523) and a heap-based buffer overflow in TIFF2PDF tool (CVE-2020-35524).
The affected packages include libtiff, libtiff-debuginfo, libtiff-tools, and others that depend on libtiff in Red Hat Enterprise Linux 8.
RHSA-2021:4241 is applicable to users of Red Hat Enterprise Linux 8 who utilize the libtiff library for handling TIFF files.