Advisories ยป MGASA-2023-0113

Updated libtiff packages fix security vulnerability

Publication date: 24 Mar 2023
Modification date: 24 Mar 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-4645

Description

LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948,
allowing attackers to cause a denial-of-service via a crafted tiff file.
(CVE-2022-4645)
                

References

SRPMS

8/core