Oval Definition:oval:org.opensuse.security:def:202234266
Revision Date:2023-06-22Version:1
Title:CVE-2022-34266
Description:

The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (application crash), a different vulnerability than CVE-2022-0562. When processing a malicious TIFF file, an invalid range may be passed as an argument to the memset() function within TIFFFetchStripThing() in tif_dirread.c. This will cause TIFFFetchStripThing() to segfault after use of an uninitialized resource.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2022-34266
SUSE CVE-2022-34266
SUSE-CU-2023:323-1
SUSE-SU-2022:3679-1
SUSE-SU-2022:3690-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Micro 5.3
SUSE Linux Enterprise Module for Basesystem 15 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Micro 5.3 is installed
  • AND libtiff5-4.0.9-150000.45.16.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND Package Information
  • libtiff-devel-4.0.9-150000.45.25.1 is installed
  • OR libtiff5-4.0.9-150000.45.25.1 is installed
  • OR libtiff5-32bit-4.0.9-150000.45.25.1 is installed
  • BACK