MGASA-2021-0098

Source
https://advisories.mageia.org/MGASA-2021-0098.html
Import Source
https://advisories.mageia.org/MGASA-2021-0098.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2021-0098
Related
Published
2021-03-04T12:26:19Z
Modified
2021-11-01T04:44:10Z
Summary
Updated libtiff packages fix security vulnerabilities
Details

The updated libtiff packages fix security vulnerabilities: - Integer overflow in tifgetimage.c (CVE-2020-35523). - Heap-based buffer overflow in TIFF2PDF tool (CVE-2020-35524). - Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the “TIFFVGetField” funtion in the component ‘libtiff/tifdir.c’. (CVE-2020-19143) - Memory allocation failure in tiff2rgba (CVE-2020-35521) - Memory allocation failure in tiff2rgba (CVE-2020-35522)

References
Credits

Affected packages