Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Debian 8: DLA-2147-1 Critical: gdal Heap Overflow in LibTIFF

debian lts
Calendar Grey March 18, 2020
Dist Debian Esm H88
gdal has released a security patch to fix a possible heap overflow vulnerability in LibTIFF. Make sure to update your gdal installations immediately!
tif_getimage.c in LibTIFF, as used in GDAL has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param"...

Summary

For Debian 8 "Jessie", this problem has been fixed in version
1.10.1+dfsg-8+deb8u2.

We recommend that you upgrade your gdal packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Best,
Utkarsh


Severity
critical
Lowest
Low
Medium
High
Critical

Package: gdal
Version: 1.10.1+dfsg-8+deb8u2
CVE ID: CVE-2019-17546

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here