|
|
Log in / Subscribe / Register

Mageia alert MGASA-2022-0087 (libtiff)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2022-0087: Updated libtiff packages fix security vulnerability
Date:  Sun, 06 Mar 2022 11:41:18 +0100
Message-ID:  <20220306104118.C869AA1714@duvel.mageia.org>
Archive-link:  Article

MGASA-2022-0087 - Updated libtiff packages fix security vulnerability Publication date: 06 Mar 2022 URL: https://advisories.mageia.org/MGASA-2022-0087.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-0561, CVE-2022-0562 Description: Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. (CVE-2022-0561) Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. (CVE-2022-0562) References: - https://bugs.mageia.org/show_bug.cgi?id=30108 - https://lists.fedoraproject.org/archives/list/package-ann... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0561 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0562 SRPMS: - 8/core/libtiff-4.2.0-1.2.mga8


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds