MGASA-2024-0077 - Updated libtiff packages fix security vulnerabilities

Publication date: 20 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0077.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2023-40745,
     CVE-2023-41175

LibTIFF is vulnerable to an integer overflow. This flaw allows remote
attackers to cause a denial of service (application crash) or possibly
execute an arbitrary code via a crafted tiff image, which triggers a
heap-based buffer overflow. (CVE-2023-40745)
A vulnerability was found in libtiff due to multiple potential integer
overflows in raw2tiff.c. This flaw allows remote attackers to cause a
denial of service or possibly execute an arbitrary code via a crafted
tiff image, which triggers a heap-based buffer overflow.
(CVE-2023-41175)

References:
- https://bugs.mageia.org/show_bug.cgi?id=32983
- https://lwn.net/Articles/965827/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40745
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41175

SRPMS:
- 9/core/libtiff-4.5.1-1.2.mga9

Mageia 2024-0077: libtiff security update

LibTIFF is vulnerable to an integer overflow

Summary

LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. (CVE-2023-40745) A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. (CVE-2023-41175)

References

- https://bugs.mageia.org/show_bug.cgi?id=32983

- https://lwn.net/Articles/965827/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40745

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41175

Resolution

MGASA-2024-0077 - Updated libtiff packages fix security vulnerabilities

SRPMS

- 9/core/libtiff-4.5.1-1.2.mga9

Severity
Publication date: 20 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0077.html
Type: security
CVE: CVE-2023-40745, CVE-2023-41175

Related News