Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 8 MGASA-2022-0087 Critical: LibTiff Denial of Service

mageia
Calendar Grey March 6, 2022
Dist Mageia Esm H88
The latest libtiff updates address significant security vulnerabilities that could cause denial of service issues in Mageia. Learn more about the findings here.
Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service...

Summary

Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. (CVE-2022-0561)
Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. (CVE-2022-0562)

References

- https://bugs.mageia.org/show_bug.cgi?id=30108

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DZEHZ35XVO2VBZ4HHCMM6J6TQIDSBQOM/

- https://www.cve.org/CVERecord?id=CVE-2022-0561

- https://www.cve.org/CVERecord?id=CVE-2022-0562

Resolution

SRPMS

- 8/core/libtiff-4.2.0-1.2.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 06 Mar 2022
URL: https://advisories.mageia.org/MGASA-2022-0087.html
Type: security
CVE: CVE-2022-0561, CVE-2022-0562

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here