|
|
Log in / Subscribe / Register

Mageia alert MGASA-2018-0246 (libtiff)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2018-0246: Updated libtiff packages fix security vulnerabilities
Date:  Wed, 16 May 2018 10:25:58 +0200
Message-ID:  <20180516082558.EB6D09FB82@duvel.mageia.org>

MGASA-2018-0246 - Updated libtiff packages fix security vulnerabilities Publication date: 16 May 2018 URL: https://advisories.mageia.org/MGASA-2018-0246.html Type: security Affected Mageia releases: 5, 6 CVE: CVE-2018-10963, CVE-2018-8905 Description: The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a different vulnerability than CVE-2017-13726. (CVE-2018-10963) In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps. (CVE-2018-8905) References: - https://bugs.mageia.org/show_bug.cgi?id=23021 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8905 SRPMS: - 6/core/libtiff-4.0.9-1.5.mga6 - 5/core/libtiff-4.0.9-1.5.mga5


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds