Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE: 2018:1826-1 Moderate: TIFF Remote Code Execution Fix

suse
Calendar Grey June 27, 2018
Scroller Suse
A new patch has been released for SUSE addressing 8 vulnerabilities in tiff, enhancing security measures and system reliability.
An update that fixes 8 vulnerabilities is now available

Summary

This update for tiff fixes the following issues: These security issues were fixed: - CVE-2017-18013: There was a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash. (bsc#1074317) - CVE-2018-10963: The TIFFWriteDirectorySec() function in tif_dirwrite.c allowed remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a different vulnerability than CVE-2017-13726. (bsc#1092949) - CVE-2018-7456: Prevent a NULL Pointer dereference in the function TIFFPrintDirectory when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013 (bsc#1082825) - CVE-2017-11613: Prevent denial of service in the TIFFOpen function.

References

#1007276 #1074317 #1082332 #1082825 #1086408

#1092949 #974621

Cross- CVE-2016-3632 CVE-2016-8331 CVE-2017-11613

CVE-2017-13726 CVE-2017-18013 CVE-2018-10963

CVE-2018-7456 CVE-2018-8905

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Desktop 12-SP3

https://www.suse.com/security/cve/CVE-2016-3632.html

https://www.suse.com/security/cve/CVE-2016-8331.html

https://www.suse.com/security/cve/CVE-2017-11613.html

https://www.suse.com/security/cve/CVE-2017-13726.html

https://www.suse.com/security/cve/CVE-2017-18013.html

https://www.suse.com/security/cve/CVE-2018-10963.html

https://www.suse.com/security/cve/CVE-2018-7456.html

Announcement ID: SUSE-SU-2018:1826-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.