VYPR

rpm package

suse/tiff&distro=SUSE Linux Enterprise Server 12 SP3-BCL

pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCL

Vulnerabilities (22)

  • CVE-2019-17546Oct 14, 2019
    affected < 4.0.9-44.45.1fixed 4.0.9-44.45.1

    tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

  • CVE-2017-17095HigDec 2, 2017
    affected < 4.0.9-44.45.1fixed 4.0.9-44.45.1

    tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.

Page 2 of 2