MGASA-2018-0444 - Updated libtiff packages fix security vulnerability

Publication date: 11 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0444.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-18661

An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer
dereference in the function LZWDecode in the file tif_lzw.c.
(CVE-2018-18661)

References:
- https://bugs.mageia.org/show_bug.cgi?id=23788
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18661

SRPMS:
- 6/core/libtiff-4.0.9-1.8.mga6

Mageia 2018-0444: libtiff security update

An issue was discovered in LibTIFF 4.0.9

Summary

An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c. (CVE-2018-18661)

References

- https://bugs.mageia.org/show_bug.cgi?id=23788

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18661

Resolution

MGASA-2018-0444 - Updated libtiff packages fix security vulnerability

SRPMS

- 6/core/libtiff-4.0.9-1.8.mga6

Severity
Publication date: 11 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0444.html
Type: security
CVE: CVE-2018-18661

Related News