Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
172

Ubuntu 23.04 LTS: USN-6428-1 Critical Denial of Service in LibTIFF

LibTIFF could be made to crash if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-6428-1 October 11, 2023 tiff vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: LibTIFF could be made to crash if it opened a specially crafted file. Software Description: - tiff: Tag Image File Format (TIFF) library Details: It was discovered that LibTIFF could be made to read out of bounds when processing certain malformed image files with the tiffcrop utility. If a user were tricked into opening a specially crafted image file, an attacker could possibly use this issue to cause tiffcrop to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: libtiff-tools 4.5.0-5ubuntu1.2 libtiff6 4.5.0-5ubuntu1.2 Ubuntu 22.04 LTS: libtiff-tools 4.3.0-6ubuntu0.6 libtiff5 4.3.0-6ubuntu0.6 Ubuntu 20.04 LTS: libtiff-tools 4.1.0+git191117-2ubuntu0.20.04.10 libtiff5 4.1.0+git191117-2ubuntu0.20.04.10 Ubuntu 18.04 LTS (Available with Ubuntu Pro): libtiff-tools 4.0.9-5ubuntu0.10+esm3 libtiff5 4.0.9-5ubuntu0.10+esm3 Ubuntu 16.04 LTS (Available with Ubuntu Pro): libtiff-tools 4.0.6-1ubuntu0.8+esm13 libtiff5 4.0.6-1ubuntu0.8+esm13 Ubuntu 14.04 LTS (Available with Ubuntu Pro): libtiff-tools 4.0.3-7ubuntu0.11+esm10 libtiff5 4.0.3-7ubuntu0.11+esm10 In general, a standardsystem update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6428-1 CVE-2023-1916 Package Information: https://launchpad.net/ubuntu/+source/tiff/4.5.0-5ubuntu1.2 https://launchpad.net/ubuntu/+source/tiff/4.3.0-6ubuntu0.6 https://launchpad.net/ubuntu/+source/tiff/4.1.0+git191117-2ubuntu0.20.04.10 . If an improperly structured image file is accessed, LibTIFF on Ubuntu may lead to a crash. To enhance security and address this vulnerability, updates are now available to rectify the problem.. LibTIFF Security, Denial of Service Update, Ubuntu Security Notice, tiffcrop Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 11, 2023 Critical Ubuntu
87

Debian 11 Bullseye: DSA-5361-1 Moderate: tiff Denial of Service

Several flaws were found in tiffcrop, a program distributed by tiff, the Tag Image File Format (TIFF) library and tools. A specially crafted tiff file can lead to an out-of-bounds write or read resulting in a denial of service. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5361-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Aron Xu February 24, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tiff CVE ID : CVE-2023-0795 CVE-2023-0796 CVE-2023-0797 CVE-2023-0798 CVE-2023-0799 CVE-2023-0800 CVE-2023-0801 CVE-2023-0802 CVE-2023-0803 CVE-2023-0804 Debian Bug : 1031632 Several flaws were found in tiffcrop, a program distributed by tiff, the Tag Image File Format (TIFF) library and tools. A specially crafted tiff file can lead to an out-of-bounds write or read resulting in a denial of service. For the stable distribution (bullseye), this problem has been fixed in version 4.2.0-1+deb11u4. We recommend that you upgrade your tiff packages. For the detailed security status of tiff please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/tiff Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ensure your TIFF packages are updated in Debian to mitigate denial of service vulnerabilities identified in tiffutil.. Debian Security Advisory,tiff software update,denial of service,TIFF flaws,tiffcrop security fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 24, 2023 Important Debian
203

Mageia: 2022-0337 Moderate: tiffcrop Out Of Bounds Exploit

libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further exploitation. (CVE-2022-2867) . MGASA-2022-0337 - Updated libtiff packages fix security vulnerability Publication date: 16 Sep 2022 URL: https://advisories.mageia.org/MGASA-2022-0337.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-2867, CVE-2022-2868, CVE-2022-2869 libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further exploitation. (CVE-2022-2867) libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop. (CVE-2022-2868) libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into opening the crafted file with tiffcrop. Triggering this flaw could cause a crash or potentially further exploitation. (CVE-2022-2869) References: - https://bugs.mageia.org/show_bug.cgi?id=30836 - - https://www.cve.org/CVERecord?id=CVE-2022-2867 - https://www.cve.org/CVERecord?id=CVE-2022-2868 - https://www.cve.org/CVERecord?id=CVE-2022-2869 SRPMS: - 8/core/libtiff-4.2.0-1.8.mga8 . Mageia patches libjpeg to address severe vulnerability permitting possible crashes and security breaches. More information can be found in the advisory.. libtiff security, tiffcrop update, Mageia advisory, out of bounds error, software exploit. . LinuxSecurity.com Team

Calendar 2 Sep 16, 2022 Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here