Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

SUSE Linux Enterprise Server 11-SP4: SUSE-SU-2018:2676-1 Moderate TIFF Fix

suse
Calendar Grey September 10, 2018
Dist Suse Esm H88
SUSE's critical security patch addresses heap overflow vulnerabilities in the TIFF image library. Ensure your software is updated to mitigate potential risks.
An update that fixes four vulnerabilities is now available

Summary

This update for tiff fixes the following issues: The following security vulnerabilities were addressed: - CVE-2015-8668: Fixed a heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff, which allowed remote attackers to execute arbitrary code or cause a denial of service via a large width field in a specially crafted BMP image. (bsc#960589) - CVE-2018-10779: Fixed a heap-based buffer over-read in TIFFWriteScanline() in tif_write.c (bsc#1092480) - CVE-2017-17942: Fixed a heap-based buffer overflow in the function PackBitsEncode in tif_packbits.c. (bsc#1074186) - CVE-2016-5319: Fixed a beap-based buffer overflow in bmp2tiff (bsc#983440) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1074186 #1092480 #960589 #983440

Cross- CVE-2015-8668 CVE-2016-5319 CVE-2017-17942

CVE-2018-10779

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2015-8668.html

https://www.suse.com/security/cve/CVE-2016-5319.html

https://www.suse.com/security/cve/CVE-2017-17942.html

https://www.suse.com/security/cve/CVE-2018-10779.html

https://bugzilla.suse.com/1074186

https://bugzilla.suse.com/1092480

https://bugzilla.suse.com/960589

https://bugzilla.suse.com/983440

Announcement ID: SUSE-SU-2018:2676-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here