Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

openSUSE: 2023:4370-1 Moderate: tiff NULL Pointer and Integer Overflow

opensuse
Calendar Grey November 6, 2023
Scroller Opensuse
This patch resolves multiple concerns in tiff, specifically focusing on memory management and pointer handling for Fedora.
This update for tiff fixes the following issues: CVE-2023-38289: Fixed a NULL pointer dereference in raw2tiff (bsc#1213589)

Description

This update for tiff fixes the following issues:

* CVE-2023-38289: Fixed a NULL pointer dereference in raw2tiff (bsc#1213589).

* CVE-2023-38288: Fixed an integer overflow in raw2tiff (bsc#1213590).

* CVE-2023-3576: Fixed a memory leak in tiffcrop (bsc#1213273).

* CVE-2020-18768: Fixed an out of bounds read in tiffcp (bsc#1214574).

* CVE-2023-26966: Fixed an out of bounds read when transforming a little-

endian file to a big-endian output (bsc#1212881)

* CVE-2023-3618: Fixed a NULL pointer dereference while encoding FAX3 files

(bsc#1213274).

* CVE-2023-2908: Fixed an undefined behavior issue when doing pointer

arithmetic on a NULL pointer (bsc#1212888).

* CVE-2023-3316: Fixed a NULL pointer dereference while opening a file in an

inaccessible path (bsc#1212535).

* CVE-2023-25433: Fixed a buffer overflow in tiffcrop (bsc#1212883).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro 5.2

zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4370=1

* SUSE Linux Enterprise Micro for Rancher 5.2

zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4370=1

* openSUSE Leap Micro 5.3

zypper in -t patch openSUSE-Leap-Micro-5.3-2023-4370=1

* openSUSE Leap Micro 5.4

zypper in -t patch openSUSE-Leap-Micro-5.4-2023-4370=1

* openSUSE Leap 15.4

zypper in -t patch openSUSE-SLE-15.4-2023-4370=1

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2023-4370=1

* SUSE Linux Enterprise Micro for Rancher 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2023-4370=1

* SUSE Linux Enterprise Micro 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2023-4370=1

* SUSE Linux Enterprise Micro for Rancher 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2023-4370=1

* SUSE Linux Enterprise Micro 5.4

zypper in -t patch...

Read the Full Advisory

Package List

* SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64)

* libtiff5-debuginfo-4.0.9-150000.45.32.1

* tiff-debuginfo-4.0.9-150000.45.32.1

* libtiff5-4.0.9-150000.45.32.1

* tiff-debugsource-4.0.9-150000.45.32.1

* SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64)

* libtiff5-debuginfo-4.0.9-150000.45.32.1

* tiff-debuginfo-4.0.9-150000.45.32.1

* libtiff5-4.0.9-150000.45.32.1

* tiff-debugsource-4.0.9-150000.45.32.1

* openSUSE Leap Micro 5.3 (aarch64 x86_64)

* libtiff5-debuginfo-4.0.9-150000.45.32.1

* tiff-debuginfo-4.0.9-150000.45.32.1

* libtiff5-4.0.9-150000.45.32.1

* tiff-debugsource-4.0.9-150000.45.32.1

* openSUSE Leap Micro 5.4 (aarch64 s390x x86_64)

* libtiff5-debuginfo-4.0.9-150000.45.32.1

* tiff-debuginfo-4.0.9-150000.45.32.1

* libtiff5-4.0.9-150000.45.32.1

* tiff-debugsource-4.0.9-150000.45.32.1

* openSUSE Leap 15.4 (x86_64)

* libtiff5-32bit-debuginfo-4.0.9-150000.45.32.1

* libtiff5-32bit-4.0.9-150000.45.32.1

* libtiff-devel-32bit-4.0.9-150000.45.32.1

* openSUSE Leap 15.4 (aarch64 ppc64le...

Read the Full Advisory

References

* bsc#1212535

* bsc#1212881

* bsc#1212883

* bsc#1212888

* bsc#1213273

* bsc#1213274

* bsc#1213589

* bsc#1213590

* bsc#1214574

## References:

* https://www.suse.com/security/cve/CVE-2020-18768.html

* https://www.suse.com/security/cve/CVE-2023-25433.html

* https://www.suse.com/security/cve/CVE-2023-26966.html

* https://www.suse.com/security/cve/CVE-2023-2908.html

* https://www.suse.com/security/cve/CVE-2023-3316.html

* https://www.suse.com/security/cve/CVE-2023-3576.html

* https://www.suse.com/security/cve/CVE-2023-3618.html

* https://www.suse.com/security/cve/CVE-2023-38288.html

* https://www.suse.com/security/cve/CVE-2023-38289.html

* https://bugzilla.suse.com/show_bug.cgi?id=1212535

* https://bugzilla.suse.com/show_bug.cgi?id=1212881

* https://bugzilla.suse.com/show_bug.cgi?id=1212883

* https://bugzilla.suse.com/show_bug.cgi?id=1212888

* https://bugzilla.suse.com/show_bug.cgi?id=1213273

* https://bugzilla.suse.com/show_bug.cgi?id=1213274

* https://bugzilla.suse.com/show_bug.cgi?id=1213589

*...

Read the Full Advisory

Announcement ID: SUSE-SU-2023:4370-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.