MGASA-2024-0077

Source
https://advisories.mageia.org/MGASA-2024-0077.html
Import Source
https://advisories.mageia.org/MGASA-2024-0077.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2024-0077
Related
Published
2024-03-20T21:19:08Z
Modified
2024-03-20T21:04:26Z
Summary
Updated libtiff packages fix security vulnerabilities
Details

LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. (CVE-2023-40745) A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. (CVE-2023-41175)

References
Credits

Affected packages