ALT-PU-2021-2853-1
Closed vulnerabilities
BDU:2020-03213
Уязвимость функции cpSeparateBufToContigBuf программного обеспечения для просмотра, редактирования и конвертирования TIFF-файлов, связанная с записью за границами буфера, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01525
Уязвимость модуля конвертации изображения TIFF в RGBA tiff2rgba библиотеки LibTIFF, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01526
Уязвимость файла tif_getimage.c библиотеки LibTIFF, позволяющая нарушителю выполнить произвольный код
BDU:2021-01527
Уязвимость модуля конвертации изображения TIFF в PDF TIFF2PDF библиотеки LibTIFF, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2021-01529
Уязвимость файла tif_read.c библиотеки LibTIFF, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2021-03591
Уязвимость компонента tif_getimage.c библиотеки LibTIFF, связанная с записью за границами буфера, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2018-12900
Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via a crafted TIFF file.
- http://bugzilla.maptools.org/show_bug.cgi?id=2798
- http://bugzilla.maptools.org/show_bug.cgi?id=2798
- RHSA-2019:2053
- RHSA-2019:2053
- RHSA-2019:3419
- RHSA-2019:3419
- https://github.com/Hack-Me/Pocs_for_Multi_Versions/tree/main/CVE-2018-12900
- https://github.com/Hack-Me/Pocs_for_Multi_Versions/tree/main/CVE-2018-12900
- [debian-lts-announce] 20191126 [SECURITY] [DLA 2009-1] tiff security update
- [debian-lts-announce] 20191126 [SECURITY] [DLA 2009-1] tiff security update
- USN-3906-1
- USN-3906-1
- USN-3906-2
- USN-3906-2
- DSA-4670
- DSA-4670
Modified: 2024-12-20
CVE-2019-17546
tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16443
- https://github.com/OSGeo/gdal/commit/21674033ee246f698887604c7af7ba1962a40ddf
- https://gitlab.com/libtiff/libtiff/commit/4bb584a35f87af42d6cf09d15e9ce8909a839145
- [debian-lts-announce] 20191126 [SECURITY] [DLA 2009-1] tiff security update
- [debian-lts-announce] 20200318 [SECURITY] [DLA 2147-1] gdal security update
- FEDORA-2020-2e9bd06377
- FEDORA-2020-6f1209bb45
- 20200121 [SECURITY] [DSA 4608-1] tiff security update
- GLSA-202003-25
- DSA-4608
- DSA-4670
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16443
- DSA-4670
- https://security.netapp.com/advisory/ntap-20241220-0007/
- DSA-4608
- GLSA-202003-25
- 20200121 [SECURITY] [DSA 4608-1] tiff security update
- FEDORA-2020-6f1209bb45
- FEDORA-2020-2e9bd06377
- [debian-lts-announce] 20200318 [SECURITY] [DLA 2147-1] gdal security update
- [debian-lts-announce] 20191126 [SECURITY] [DLA 2009-1] tiff security update
- https://gitlab.com/libtiff/libtiff/commit/4bb584a35f87af42d6cf09d15e9ce8909a839145
- https://github.com/OSGeo/gdal/commit/21674033ee246f698887604c7af7ba1962a40ddf
Modified: 2024-11-21
CVE-2020-35521
A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service.
Modified: 2024-11-21
CVE-2020-35522
In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack.
Modified: 2024-11-21
CVE-2020-35523
An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
- https://bugzilla.redhat.com/show_bug.cgi?id=1932040
- https://bugzilla.redhat.com/show_bug.cgi?id=1932040
- https://gitlab.com/libtiff/libtiff/-/commit/c8d613ef497058fe653c467fc84c70a62a4a71b2
- https://gitlab.com/libtiff/libtiff/-/commit/c8d613ef497058fe653c467fc84c70a62a4a71b2
- https://gitlab.com/libtiff/libtiff/-/merge_requests/160
- https://gitlab.com/libtiff/libtiff/-/merge_requests/160
- [debian-lts-announce] 20210627 [SECURITY] [DLA 2694-1] tiff security update
- [debian-lts-announce] 20210627 [SECURITY] [DLA 2694-1] tiff security update
- FEDORA-2021-1bf4f2f13a
- FEDORA-2021-1bf4f2f13a
- GLSA-202104-06
- GLSA-202104-06
- https://security.netapp.com/advisory/ntap-20210521-0009/
- https://security.netapp.com/advisory/ntap-20210521-0009/
- DSA-4869
- DSA-4869
Modified: 2024-11-21
CVE-2020-35524
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
- https://bugzilla.redhat.com/show_bug.cgi?id=1932044
- https://bugzilla.redhat.com/show_bug.cgi?id=1932044
- https://gitlab.com/libtiff/libtiff/-/merge_requests/159
- https://gitlab.com/libtiff/libtiff/-/merge_requests/159
- https://gitlab.com/rzkn/libtiff/-/commit/7be2e452ddcf6d7abca88f41d3761e6edab72b22
- https://gitlab.com/rzkn/libtiff/-/commit/7be2e452ddcf6d7abca88f41d3761e6edab72b22
- [debian-lts-announce] 20210627 [SECURITY] [DLA 2694-1] tiff security update
- [debian-lts-announce] 20210627 [SECURITY] [DLA 2694-1] tiff security update
- FEDORA-2021-1bf4f2f13a
- FEDORA-2021-1bf4f2f13a
- GLSA-202104-06
- GLSA-202104-06
- https://security.netapp.com/advisory/ntap-20210521-0009/
- https://security.netapp.com/advisory/ntap-20210521-0009/
- DSA-4869
- DSA-4869