tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "binaries": [ { "binary_version": "1.10.1+dfsg-5ubuntu1+esm1", "binary_name": "gdal-bin" }, { "binary_version": "1.10.1+dfsg-5ubuntu1+esm1", "binary_name": "libgdal-dev" }, { "binary_version": "1.10.1+dfsg-5ubuntu1+esm1", "binary_name": "libgdal-java" }, { "binary_version": "1.10.1+dfsg-5ubuntu1+esm1", "binary_name": "libgdal-perl" }, { "binary_version": "1.10.1+dfsg-5ubuntu1+esm1", "binary_name": "libgdal1-dev" }, { "binary_version": "1.10.1+dfsg-5ubuntu1+esm1", "binary_name": "libgdal1h" }, { "binary_version": "1.10.1+dfsg-5ubuntu1+esm1", "binary_name": "python-gdal" }, { "binary_version": "1.10.1+dfsg-5ubuntu1+esm1", "binary_name": "python3-gdal" } ] }
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "binaries": [ { "binary_version": "4.0.3-7ubuntu0.11+esm6", "binary_name": "libtiff-opengl" }, { "binary_version": "4.0.3-7ubuntu0.11+esm6", "binary_name": "libtiff-tools" }, { "binary_version": "4.0.3-7ubuntu0.11+esm6", "binary_name": "libtiff4-dev" }, { "binary_version": "4.0.3-7ubuntu0.11+esm6", "binary_name": "libtiff5" }, { "binary_version": "4.0.3-7ubuntu0.11+esm6", "binary_name": "libtiff5-alt-dev" }, { "binary_version": "4.0.3-7ubuntu0.11+esm6", "binary_name": "libtiff5-dev" }, { "binary_version": "4.0.3-7ubuntu0.11+esm6", "binary_name": "libtiffxx5" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "4.0.6-1ubuntu0.7", "binary_name": "libtiff-opengl" }, { "binary_version": "4.0.6-1ubuntu0.7", "binary_name": "libtiff-tools" }, { "binary_version": "4.0.6-1ubuntu0.7", "binary_name": "libtiff5" }, { "binary_version": "4.0.6-1ubuntu0.7", "binary_name": "libtiff5-dev" }, { "binary_version": "4.0.6-1ubuntu0.7", "binary_name": "libtiffxx5" } ] }
{ "binaries": [ { "binary_version": "1.11.3+dfsg-3build2", "binary_name": "gdal-bin" }, { "binary_version": "1.11.3+dfsg-3build2", "binary_name": "libgdal-dev" }, { "binary_version": "1.11.3+dfsg-3build2", "binary_name": "libgdal-java" }, { "binary_version": "1.11.3+dfsg-3build2", "binary_name": "libgdal-perl" }, { "binary_version": "1.11.3+dfsg-3build2", "binary_name": "libgdal1-dev" }, { "binary_version": "1.11.3+dfsg-3build2", "binary_name": "libgdal1i" }, { "binary_version": "1.11.3+dfsg-3build2", "binary_name": "python-gdal" }, { "binary_version": "1.11.3+dfsg-3build2", "binary_name": "python3-gdal" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "4.0.9-5ubuntu0.3", "binary_name": "libtiff-dev" }, { "binary_version": "4.0.9-5ubuntu0.3", "binary_name": "libtiff-opengl" }, { "binary_version": "4.0.9-5ubuntu0.3", "binary_name": "libtiff-tools" }, { "binary_version": "4.0.9-5ubuntu0.3", "binary_name": "libtiff5" }, { "binary_version": "4.0.9-5ubuntu0.3", "binary_name": "libtiff5-dev" }, { "binary_version": "4.0.9-5ubuntu0.3", "binary_name": "libtiffxx5" } ] }
{ "binaries": [ { "binary_version": "5.9.5+dfsg-0ubuntu2", "binary_name": "libqt5webengine-data" }, { "binary_version": "5.9.5+dfsg-0ubuntu2", "binary_name": "libqt5webengine5" }, { "binary_version": "5.9.5+dfsg-0ubuntu2", "binary_name": "libqt5webenginecore5" }, { "binary_version": "5.9.5+dfsg-0ubuntu2", "binary_name": "libqt5webenginewidgets5" }, { "binary_version": "5.9.5+dfsg-0ubuntu2", "binary_name": "qml-module-qtwebengine" }, { "binary_version": "5.9.5+dfsg-0ubuntu2", "binary_name": "qtwebengine5-dev" }, { "binary_version": "5.9.5+dfsg-0ubuntu2", "binary_name": "qtwebengine5-dev-tools" }, { "binary_version": "5.9.5+dfsg-0ubuntu2", "binary_name": "qtwebengine5-doc-html" }, { "binary_version": "5.9.5+dfsg-0ubuntu2", "binary_name": "qtwebengine5-examples" }, { "binary_version": "5.9.5+dfsg-0ubuntu2", "binary_name": "qtwebengine5-private-dev" } ] }
{ "binaries": [ { "binary_version": "5.12.8+dfsg-0ubuntu1.1", "binary_name": "libqt5webengine-data" }, { "binary_version": "5.12.8+dfsg-0ubuntu1.1", "binary_name": "libqt5webengine5" }, { "binary_version": "5.12.8+dfsg-0ubuntu1.1", "binary_name": "libqt5webenginecore5" }, { "binary_version": "5.12.8+dfsg-0ubuntu1.1", "binary_name": "libqt5webenginewidgets5" }, { "binary_version": "5.12.8+dfsg-0ubuntu1.1", "binary_name": "qml-module-qtwebengine" }, { "binary_version": "5.12.8+dfsg-0ubuntu1.1", "binary_name": "qtwebengine5-dev" }, { "binary_version": "5.12.8+dfsg-0ubuntu1.1", "binary_name": "qtwebengine5-dev-tools" }, { "binary_version": "5.12.8+dfsg-0ubuntu1.1", "binary_name": "qtwebengine5-doc-html" }, { "binary_version": "5.12.8+dfsg-0ubuntu1.1", "binary_name": "qtwebengine5-examples" }, { "binary_version": "5.12.8+dfsg-0ubuntu1.1", "binary_name": "qtwebengine5-private-dev" } ] }
{ "binaries": [ { "binary_version": "5.15.9+dfsg-1", "binary_name": "libqt5pdf5" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "libqt5pdfwidgets5" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "libqt5webengine-data" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "libqt5webengine5" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "libqt5webenginecore5" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "libqt5webenginewidgets5" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "qml-module-qtquick-pdf" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "qml-module-qtwebengine" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "qt5-image-formats-plugin-pdf" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "qtpdf5-dev" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "qtpdf5-doc-html" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "qtpdf5-examples" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "qtwebengine5-dev" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "qtwebengine5-dev-tools" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "qtwebengine5-doc-html" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "qtwebengine5-examples" }, { "binary_version": "5.15.9+dfsg-1", "binary_name": "qtwebengine5-private-dev" } ] }
{ "binaries": [ { "binary_version": "5.15.16+dfsg-3", "binary_name": "libqt5pdf5" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "libqt5pdfwidgets5" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "libqt5webengine-data" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "libqt5webengine5" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "libqt5webenginecore5" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "libqt5webenginewidgets5" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "qml-module-qtquick-pdf" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "qml-module-qtwebengine" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "qt5-image-formats-plugin-pdf" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "qtpdf5-dev" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "qtpdf5-doc-html" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "qtpdf5-examples" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "qtwebengine5-dev" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "qtwebengine5-dev-tools" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "qtwebengine5-doc-html" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "qtwebengine5-examples" }, { "binary_version": "5.15.16+dfsg-3", "binary_name": "qtwebengine5-private-dev" } ] }
{ "binaries": [ { "binary_version": "5.15.18+dfsg-2", "binary_name": "libqt5pdf5" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "libqt5pdfwidgets5" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "libqt5webengine-data" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "libqt5webengine5" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "libqt5webenginecore5" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "libqt5webenginewidgets5" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "qml-module-qtquick-pdf" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "qml-module-qtwebengine" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "qt5-image-formats-plugin-pdf" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "qtpdf5-dev" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "qtpdf5-doc-html" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "qtpdf5-examples" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "qtwebengine5-dev" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "qtwebengine5-dev-tools" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "qtwebengine5-doc-html" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "qtwebengine5-examples" }, { "binary_version": "5.15.18+dfsg-2", "binary_name": "qtwebengine5-private-dev" } ] }