{"id":"openSUSE-SU-2022:0480-1","summary":"Security update for tiff","details":"This update for tiff fixes the following issues:\n\n- CVE-2017-17095: Fixed DoS in tools/pal2rgb.c in pal2rgb (bsc#1071031).\n- CVE-2019-17546: Fixed integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image (bsc#1154365).\n- CVE-2020-19131: Fixed buffer overflow in tiffcrop that may cause DoS via the invertImage() function (bsc#1190312).\n- CVE-2020-35521: Fixed memory allocation failure in tif_read.c (bsc#1182808).\n- CVE-2020-35522: Fixed memory allocation failure in tif_pixarlog.c (bsc#1182809).\n- CVE-2020-35523: Fixed integer overflow in tif_getimage.c (bsc#1182811).\n- CVE-2020-35524: Fixed heap-based buffer overflow in TIFF2PDF tool (bsc#1182812).\n- CVE-2022-22844: Fixed out-of-bounds read in _TIFFmemcpy in tif_unix.c (bsc#1194539).\n","modified":"2026-02-04T02:38:26.804883Z","published":"2022-02-17T14:11:19Z","related":["CVE-2017-17095","CVE-2019-17546","CVE-2020-19131","CVE-2020-35521","CVE-2020-35522","CVE-2020-35523","CVE-2020-35524","CVE-2022-22844"],"upstream":["CVE-2017-17095","CVE-2019-17546","CVE-2020-19131","CVE-2020-35521","CVE-2020-35522","CVE-2020-35523","CVE-2020-35524","CVE-2022-22844"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7OF4G5SOPBRKT4CZJV5MAQLV5LXXFO62/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1071031"},{"type":"REPORT","url":"https://bugzilla.suse.com/1154365"},{"type":"REPORT","url":"https://bugzilla.suse.com/1182808"},{"type":"REPORT","url":"https://bugzilla.suse.com/1182809"},{"type":"REPORT","url":"https://bugzilla.suse.com/1182811"},{"type":"REPORT","url":"https://bugzilla.suse.com/1182812"},{"type":"REPORT","url":"https://bugzilla.suse.com/1190312"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194539"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-17095"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17546"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-19131"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-35521"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-35522"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-35523"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-35524"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-22844"}],"affected":[{"package":{"name":"tiff","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/tiff&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.9-45.5.1"}]}],"ecosystem_specific":{"binaries":[{"libtiff5":"4.0.9-45.5.1","tiff":"4.0.9-45.5.1","libtiff-devel-32bit":"4.0.9-45.5.1","libtiff-devel":"4.0.9-45.5.1","libtiff5-32bit":"4.0.9-45.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:0480-1.json"}}],"schema_version":"1.7.3"}