Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2018:1472-1 Moderate: TIFF Denial Of Service Issues

suse
Calendar Grey May 30, 2018
Scroller Suse
The latest patch addresses various vulnerabilities in png for OpenSUSE, improving overall security and safeguarding against potential external threats.
An update that solves 14 vulnerabilities and has two fixes is now available

Summary

This update for tiff fixes the following issues: Security issues fixed: - CVE-2016-5315: The setByteArray function in tif_dir.c allowed remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image. (bsc#984809) - CVE-2016-10267: LibTIFF allowed remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_ojpeg.c:816:8. (bsc#1017694) - CVE-2016-10269: LibTIFF allowed remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 512" and libtiff/tif_unix.c:340:2. (bsc#1031254) - CVE-2016-10270: LibTIFF allowed remote attackers to cause a denial of

References

#1017694 #1031250 #1031254 #1033109 #1033111

#1033112 #1033113 #1033120 #1033126 #1033127

#1033129 #1074317 #984808 #984809 #984831

#987351

Cross- CVE-2016-10267 CVE-2016-10269 CVE-2016-10270

CVE-2016-5314 CVE-2016-5315 CVE-2017-18013

CVE-2017-7593 CVE-2017-7595 CVE-2017-7596

CVE-2017-7597 CVE-2017-7599 CVE-2017-7600

CVE-2017-7601 CVE-2017-7602

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2016-10267.html

https://www.suse.com/security/cve/CVE-2016-10269.html

https://www.suse.com/security/cve/CVE-2016-10270.html

https://www.suse.com/security/cve/CVE-2016-5314.html

Announcement ID: SUSE-SU-2018:1472-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.