LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tifopen.c, tiflzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "42.2"
}
],
"cpe": "cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "42.3"
}
],
"cpe": "cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12-sp2"
}
],
"cpe": "cpe:2.3:o:suse:linux_enterprise_desktop:12:sp2:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12-sp3"
}
],
"cpe": "cpe:2.3:o:suse:linux_enterprise_desktop:12:sp3:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12-sp2"
}
],
"cpe": "cpe:2.3:o:suse:linux_enterprise_server:12:sp2:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12-sp2"
}
],
"cpe": "cpe:2.3:o:suse:linux_enterprise_server:12:sp2:*:*:*:*:raspberry_pi:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12-sp3"
}
],
"cpe": "cpe:2.3:o:suse:linux_enterprise_server:12:sp3:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12-sp2"
}
],
"cpe": "cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp2:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12-sp3"
}
],
"cpe": "cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp3:*:*:*:*:*:*"
}
]
}{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "4.0.8"
}
],
"cpe": "cpe:2.3:a:libtiff:libtiff:4.0.8:*:*:*:*:*:*:*"
}