First published: Wed Jun 21 2023(Updated: )
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.<br>Security Fix(es):<br><li> libtiff: heap-based buffer overflow in processCropSelections() in tools/tiffcrop.c (CVE-2022-48281)</li> <li> libtiff: out-of-bounds read in extractContigSamplesShifted16bits() in tools/tiffcrop.c (CVE-2023-0795)</li> <li> libtiff: out-of-bounds read in extractContigSamplesShifted24bits() in tools/tiffcrop.c (CVE-2023-0796)</li> <li> libtiff: out-of-bounds read in _TIFFmemcpy() in libtiff/tif_unix.c when called by functions in tools/tiffcrop.c (CVE-2023-0797)</li> <li> libtiff: out-of-bounds read in extractContigSamplesShifted8bits() in tools/tiffcrop.c (CVE-2023-0798)</li> <li> libtiff: use-after-free in extractContigSamplesShifted32bits() in tools/tiffcrop.c (CVE-2023-0799)</li> <li> libtiff: out-of-bounds write in extractContigSamplesShifted16bits() in tools/tiffcrop.c (CVE-2023-0800)</li> <li> libtiff: out-of-bounds write in _TIFFmemcpy() in libtiff/tif_unix.c when called by functions in tools/tiffcrop.c (CVE-2023-0801)</li> <li> libtiff: out-of-bounds write in extractContigSamplesShifted32bits() in tools/tiffcrop.c (CVE-2023-0802)</li> <li> libtiff: out-of-bounds write in extractContigSamplesShifted16bits() in tools/tiffcrop.c (CVE-2023-0803)</li> <li> libtiff: out-of-bounds write in extractContigSamplesShifted24bits() in tools/tiffcrop.c (CVE-2023-0804)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libtiff | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-debuginfo | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-debuginfo | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-debugsource | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-debugsource | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-devel | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-devel | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-tools-debuginfo | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-tools-debuginfo | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-debuginfo | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-debugsource | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-devel | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-tools-debuginfo | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff | <4.4.0-8.el9_2.aa | 4.4.0-8.el9_2.aa |
redhat/libtiff-debuginfo | <4.4.0-8.el9_2.aa | 4.4.0-8.el9_2.aa |
redhat/libtiff-debugsource | <4.4.0-8.el9_2.aa | 4.4.0-8.el9_2.aa |
redhat/libtiff-devel | <4.4.0-8.el9_2.aa | 4.4.0-8.el9_2.aa |
redhat/libtiff-tools-debuginfo | <4.4.0-8.el9_2.aa | 4.4.0-8.el9_2.aa |
redhat/libtiff-tools | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-tools | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
redhat/libtiff-tools | <4.4.0-8.el9_2.aa | 4.4.0-8.el9_2.aa |
redhat/libtiff-tools | <4.4.0-8.el9_2 | 4.4.0-8.el9_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.