MGASA-2016-0361

Source
https://advisories.mageia.org/MGASA-2016-0361.html
Import Source
https://advisories.mageia.org/MGASA-2016-0361.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2016-0361
Related
Published
2016-11-02T08:43:33Z
Modified
2016-11-02T08:35:09Z
Summary
Updated libtiff packages fix security vulnerability
Details

The TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving the ma variable (CVE-2016-3658).

They also fix:

An out-of-bound read of up to 3 bytes in readContigTilesIntoBuffer().

An out-of-bound read on some tiled images.

Segfault when specifying -r without argument (fax2tiff).

References
Credits

Affected packages