Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Ubuntu 16.04 ESM: USN-5705-1 Severe LibTIFF Memory Vulnerabilities

Ubuntu Large Esm H500
Several security issues were fixed in LibTIFF.
=========================================================================Ubuntu Security Notice USN-5705-1
October 27, 2022

tiff vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

Several security issues were fixed in LibTIFF.

Software Description:
- tiff: Tag Image File Format (TIFF) library

Details:

Chintan Shah discovered that LibTIFF incorrectly handled memory in
certain conditions. An attacker could trick a user into processing a 
specially crafted image file and potentially use this issue to allow for 
information disclosure or to cause the application to crash.
(CVE-2022-3570)

It was discovered that LibTIFF incorrectly handled memory in certain
conditions. An attacker could trick a user into processing a specially
crafted tiff file and potentially use this issue to cause a denial of 
service. (CVE-2022-3598)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
   libtiff-tools                   4.0.6-1ubuntu0.8+esm6

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-5705-1
   CVE-2022-3570, CVE-2022-3598

Ubuntu 16.04 ESM: USN-5705-1 Severe LibTIFF Memory Vulnerabilities

ubuntu
Calendar Grey October 27, 2022
Dist Ubuntu Esm H88
A number of vulnerabilities addressed in Ubuntu 16.04 ESM's LibTIFF. Instructions for updating and details on the security flaws included.
Several security issues were fixed in LibTIFF.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libtiff-tools 4.0.6-1ubuntu0.8+esm6 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5705-1

CVE-2022-3570, CVE-2022-3598

Severity
critical
Lowest
Low
Medium
High
Critical

October 27, 2022

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here