Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2020:1234-2 Moderate: png Remote Code Execution Patches

suse
Calendar Grey July 5, 2018
Scroller Suse
SUSE Security Update for libcurl tackles urgent vulnerabilities and includes guidance for patch implementation.
An update that fixes 5 vulnerabilities is now available

Summary

This update for tiff fixes the following security issues: These security issues were fixed: - CVE-2017-18013: Fixed a NULL pointer dereference in the tif_print.cTIFFPrintDirectory function that could have lead to denial of service (bsc#1074317). - CVE-2018-10963: Fixed an assertion failure in the TIFFWriteDirectorySec() function in tif_dirwrite.c, which allowed remote attackers to cause a denial of service via a crafted file (bsc#1092949). - CVE-2018-7456: Prevent a NULL Pointer dereference in the function TIFFPrintDirectory when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013 (bsc#1082825). - CVE-2017-11613: Prevent denial of service in the TIFFOpen function. During the TIFFOpen process, td_imagelength is not checked. The value of

References

#1074317 #1082332 #1082825 #1086408 #1092949

Cross- CVE-2017-11613 CVE-2017-18013 CVE-2018-10963

CVE-2018-7456 CVE-2018-8905

Affected Products:

SUSE Linux Enterprise Module for Desktop Applications 15

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2017-11613.html

https://www.suse.com/security/cve/CVE-2017-18013.html

https://www.suse.com/security/cve/CVE-2018-10963.html

https://www.suse.com/security/cve/CVE-2018-7456.html

https://www.suse.com/security/cve/CVE-2018-8905.html

https://bugzilla.suse.com/1074317

https://bugzilla.suse.com/1082332

https://bugzilla.suse.com/1082825

https://bugzilla.suse.com/1086408

https://bugzilla.suse.com/1092949

Announcement ID: SUSE-SU-2018:1889-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.