An update that solves 2 vulnerabilities can now be installed.. # tkimg-2.1.0-1.1 on GA media Announcement ID: openSUSE-SU-2025:15556-1 Rating: moderate Cross-References: * CVE-2025-8851 * CVE-2025-9165 CVSS scores: * CVE-2025-8851 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2025-8851 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-9165 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-9165 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the tkimg-2.1.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * tkimg 2.1.0-1.1 * tkimg-devel 2.1.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-8851.html * https://www.suse.com/security/cve/CVE-2025-9165.html . The recent tkimg 2.1.0-1.1 update resolves several moderate security vulnerabilities in openSUSE Tumbleweed.. openSUSE Tumbleweed,timing security update,tkimg CVE-2025-8851. . LinuxSecurity.com Team
Update to 1.4.16. Fixes CVE-2023-6277 (in bundled libtiff).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-e812bddc51 2024-01-14 00:59:11.840818 -------------------------------------------------------------------------------- Name : tkimg Product : Fedora 39 Version : 1.4.16 Release : 1.fc39 URL : https://sourceforge.net/projects/tkimg/ Summary : Image support library for Tk Description : This package contains a collection of image format handlers for the Tk photo image type, and a new image type, pixmaps. -------------------------------------------------------------------------------- Update Information: Update to 1.4.16. Fixes CVE-2023-6277 (in bundled libtiff). -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 5 2024 Tom Callaway - 1.4.16-1 - update to 1.4.16 - apply upstream (libtiff) fix for CVE-2023-6277 - update license tag * Fri Dec 8 2023 Florian Weimer - 1.4.14-5 - Backport part of an upstream patch to fix C compatibility issues -------------------------------------------------------------------------------- References: [ 1 ] Bug #2251311 - CVE-2023-6277 libtiff: Out-of-memory in TIFFOpen via a craft file https://bugzilla.redhat.com/show_bug.cgi?id=2251311 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-e812bddc51' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 1.4.16. Fixes CVE-2023-6277 (in bundled libtiff).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-43b9d9bff9 2024-01-14 00:46:47.780334 -------------------------------------------------------------------------------- Name : tkimg Product : Fedora 38 Version : 1.4.16 Release : 1.fc38 URL : https://sourceforge.net/projects/tkimg/ Summary : Image support library for Tk Description : This package contains a collection of image format handlers for the Tk photo image type, and a new image type, pixmaps. -------------------------------------------------------------------------------- Update Information: Update to 1.4.16. Fixes CVE-2023-6277 (in bundled libtiff). -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 5 2024 Tom Callaway - 1.4.16-1 - update to 1.4.16 - apply upstream (libtiff) fix for CVE-2023-6277 - update license tag * Fri Dec 8 2023 Florian Weimer - 1.4.14-5 - Backport part of an upstream patch to fix C compatibility issues * Sat Jul 22 2023 Fedora Release Engineering - 1.4.14-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2251311 - CVE-2023-6277 libtiff: Out-of-memory in TIFFOpen via a craft file https://bugzilla.redhat.com/show_bug.cgi?id=2251311 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-43b9d9bff9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Apply upstream libtiff fix for CVE-2022-4645. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-40b675d7ae 2023-03-16 18:18:56.871804 --------------------------------------------------------------------------------Name : tkimg Product : Fedora 36 Version : 1.4.14 Release : 3.fc36 URL : https://sourceforge.net/projects/tkimg/ Summary : Image support library for Tk Description : This package contains a collection of image format handlers for the Tk photo image type, and a new image type, pixmaps. --------------------------------------------------------------------------------Update Information: Apply upstream libtiff fix for CVE-2022-4645 --------------------------------------------------------------------------------ChangeLog: * Tue Mar 7 2023 Tom Callaway - 1.4.14-3 - apply upstream libtiff fix for CVE-2022-4645 * Sat Jan 21 2023 Fedora Release Engineering - 1.4.14-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2176220 - CVE-2022-4645 libtiff: out-of-bounds read in tiffcp in tools/tiffcp.c https://bugzilla.redhat.com/show_bug.cgi?id=2176220 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-40b675d7ae' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.