AlmaLinux 2302 Published by

A libtiff security update has been released for AlmaLinux 9.



ALSA-2023:0302 Moderate: libtiff security update


Type:
security

Severity:
moderate

Release date:
2023-01-24

Description
Security Fix(es):
* LibTiff: DoS from Divide By Zero Error (CVE-2022-2056, CVE-2022-2057, CVE-2022-2058)
* libtiff: Double free or corruption in rotateImage() function at tiffcrop.c (CVE-2022-2519)
* libtiff: tiffcrop: heap-buffer-overflow in extractImageSection in tiffcrop.c (CVE-2022-2953)
* libtiff: Assertion fail in rotateImage() function at tiffcrop.c (CVE-2022-2520)
* libtiff: Invalid pointer free operation in TIFFClose() at tif_close.c (CVE-2022-2521)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References:
RHSA-2023:0302
CVE-2022-2056
CVE-2022-2057
CVE-2022-2058
CVE-2022-2519
CVE-2022-2520
CVE-2022-2521
CVE-2022-2953
ALSA-2023:0302

Updates packages:
libtiff-devel-4.4.0-5.el9_1.aarch64.rpm
libtiff-4.4.0-5.el9_1.aarch64.rpm
libtiff-devel-4.4.0-5.el9_1.i686.rpm
libtiff-4.4.0-5.el9_1.i686.rpm
libtiff-4.4.0-5.el9_1.ppc64le.rpm
libtiff-devel-4.4.0-5.el9_1.ppc64le.rpm
libtiff-4.4.0-5.el9_1.s390x.rpm
libtiff-devel-4.4.0-5.el9_1.s390x.rpm
libtiff-tools-4.4.0-5.el9_1.x86_64.rpm
libtiff-tools-4.4.0-5.el9_1.aarch64.rpm
libtiff-tools-4.4.0-5.el9_1.ppc64le.rpm
libtiff-tools-4.4.0-5.el9_1.s390x.rpm

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

  ALSA-2023:0302 Moderate: libtiff security update