RHSA-2023:0095: Moderate: libtiff security update
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.Security Fix(es): LibTiff: DoS from Divide By Zero Error (CVE-2022-2056, CVE-2022-2057, CVE-2022-2058) libtiff: Double free or corruption in rotateImage() function at tiffcrop.c (CVE-2022-2519) libtiff: uint32t underflow leads to out of bounds read and write in tiffcrop.c (CVE-2022-2867) libtiff: tiffcrop.c has uint32t underflow which leads to out of bounds read and write in extractContigSamples8bits() (CVE-2022-2869) libtiff: tiffcrop: heap-buffer-overflow in extractImageSection in tiffcrop.c (CVE-2022-2953) libtiff: Assertion fail in rotateImage() function at tiffcrop.c (CVE-2022-2520) libtiff: Invalid pointer free operation in TIFFClose() at tifclose.c (CVE-2022-2521) libtiff: Invalid cropwidth and/or croplength could cause an out-of-bounds read in reverseSamples16bits() (CVE-2022-2868) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libtiffto a version that resolves this vulnerability.Fixed in 4.0.9-26.el8_7 - Upgrade
Upgrade
redhat/libtiff-debuginfoto a version that resolves this vulnerability.Fixed in 4.0.9-26.el8_7 - Upgrade
Upgrade
redhat/libtiff-debugsourceto a version that resolves this vulnerability.Fixed in 4.0.9-26.el8_7 - Upgrade
Upgrade
redhat/libtiff-develto a version that resolves this vulnerability.Fixed in 4.0.9-26.el8_7 - Upgrade
Upgrade
redhat/libtiff-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.0.9-26.el8_7 - Upgrade
Upgrade
redhat/libtiffto a version that resolves this vulnerability.Fixed in 4.0.9-26.el8_7.aa - Upgrade
Upgrade
redhat/libtiff-debuginfoto a version that resolves this vulnerability.Fixed in 4.0.9-26.el8_7.aa - Upgrade
Upgrade
redhat/libtiff-debugsourceto a version that resolves this vulnerability.Fixed in 4.0.9-26.el8_7.aa - Upgrade
Upgrade
redhat/libtiff-develto a version that resolves this vulnerability.Fixed in 4.0.9-26.el8_7.aa - Upgrade
Upgrade
redhat/libtiff-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.0.9-26.el8_7.aa - Upgrade
Upgrade
redhat/libtiff-toolsto a version that resolves this vulnerability.Fixed in 4.0.9-26.el8_7 - Upgrade
Upgrade
redhat/libtiff-toolsto a version that resolves this vulnerability.Fixed in 4.0.9-26.el8_7.aa - Operational
Restart all running applications linked against libtiff after applying the update so the changes take effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0095?
The severity of RHSA-2023:0095 has been classified as moderate.
How do I fix RHSA-2023:0095?
You can fix RHSA-2023:0095 by updating the libtiff package to version 4.0.9-26.el8_7.
What vulnerabilities are addressed in RHSA-2023:0095?
RHSA-2023:0095 addresses DoS vulnerabilities from divide by zero errors and a double free or corruption issue in the libtiff package.
Which versions of libtiff are affected by RHSA-2023:0095?
Versions of libtiff prior to 4.0.9-26.el8_7 are affected by RHSA-2023:0095.
Is there a workaround for RHSA-2023:0095?
Currently, it is recommended to apply the update to resolve the vulnerabilities in RHSA-2023:0095 instead of implementing a workaround.