Advisories ยป MGASA-2022-0240

Updated libtiff packages fix security vulnerability

Publication date: 24 Jun 2022
Modification date: 24 Jun 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-1354 , CVE-2022-1355 , CVE-2022-1622 , CVE-2022-1623

Description

Heap-buffer-overflow in TIFFReadRawDataStriped() in tiffinfo.c.
(CVE-2022-1354)
Stack-buffer-overflow in tiffcp.c in main(). (CVE-2022-1355)
Out-of-bounds read in LZWDecode. (CVE-2022-1622, CVE-2022-1623)
                

References

SRPMS

8/core