Oval Definition:oval:com.redhat.rhsa:def:20192053
Revision Date:2019-08-06Version:635
Title:RHSA-2019:2053: libtiff security update (Moderate)
Description:The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.

Security Fix(es):

  • libtiff: buffer overflow in gif2tiff (CVE-2016-3186)

  • libtiff: Heap-based buffer overflow in the cpSeparateBufToContigBuf function resulting in a denial of service or possibly code execution (CVE-2018-12900)

  • libtiff: Out-of-bounds write in tif_jbig.c (CVE-2018-18557)

  • libtiff: NULL pointer dereference in tif_print.c:TIFFPrintDirectory() causes a denial of service (CVE-2018-7456)

  • libtiff: heap-based buffer overflow in tif_lzw.c:LZWDecodeCompat() allows for denial of service (CVE-2018-8905)

  • libtiff: heap-based buffer over-read in TIFFWriteScanline function in tif_write.c (CVE-2018-10779)

  • libtiff: reachable assertion in TIFFWriteDirectorySec function in tif_dirwrite.c (CVE-2018-10963)

  • libtiff: Integer overflow in multiply_ms in tools/ppm2tiff.c (CVE-2018-17100)

  • libtiff: Two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c (CVE-2018-17101)

  • libtiff: tiff2bw tool failed memory allocation leads to crash (CVE-2018-18661)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-3186
    CVE-2018-10779
    CVE-2018-10963
    CVE-2018-12900
    CVE-2018-17100
    CVE-2018-17101
    CVE-2018-18557
    CVE-2018-18661
    CVE-2018-7456
    CVE-2018-8905
    RHSA-2019:2053
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • libtiff is earlier than 0:4.0.3-32.el7
  • AND libtiff is signed with Red Hat redhatrelease2 key
  • libtiff-devel is earlier than 0:4.0.3-32.el7
  • AND libtiff-devel is signed with Red Hat redhatrelease2 key
  • libtiff-static is earlier than 0:4.0.3-32.el7
  • AND libtiff-static is signed with Red Hat redhatrelease2 key
  • libtiff-tools is earlier than 0:4.0.3-32.el7
  • AND libtiff-tools is signed with Red Hat redhatrelease2 key
  • BACK