Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2022:2647-3 Low: tiff Update for Denial of Service Vulnerability

suse
Calendar Grey September 1, 2022
Dist Suse Esm H88
SUSE has released an update that resolves three low-severity vulnerabilities found in tiff. The update includes detailed guidance for users on how to install the necessary patches.
An update that fixes three vulnerabilities is now available

Summary

This update for tiff fixes the following issues: - CVE-2022-2056: Fixed a division by zero denial of service (bsc#1201176). - CVE-2022-2057: Fixed a division by zero denial of service (bsc#1201175). - CVE-2022-2058: Fixed a division by zero denial of service (bsc#1201174). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap Micro 5.2: zypper in -t patch openSUSE-Leap-Micro-5.2-2022-2647=1 Package List: - openSUSE Leap Micro 5.2 (aarch64 x86_64): libtiff5-4.0.9-150000.45.11.1 libtiff5-debuginfo-4.0.9-150000.45.11.1 tiff-debuginfo-4.0.9-150000.45.11.1 tiff-debugsource-4.0.9-150000.45.11.1

References

#1201174 #1201175 #1201176

Cross- CVE-2022-2056 CVE-2022-2057 CVE-2022-2058

CVSS scores:

CVE-2022-2056 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2022-2056 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

CVE-2022-2057 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2022-2057 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

CVE-2022-2058 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2022-2058 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Affected Products:

openSUSE Leap Micro 5.2

https://www.suse.com/security/cve/CVE-2022-2056.html

https://www.suse.com/security/cve/CVE-2022-2057.html

https://www.suse.com/security/cve/CVE-2022-2058.html

Severity
low
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:2647-2
Rating: low

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here