{"affected":[{"ecosystem_specific":{"binaries":[{"libtiff5":"4.0.9-44.15.2","libtiff5-32bit":"4.0.9-44.15.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP3","name":"tiff","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.9-44.15.2"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libtiff-devel":"4.0.9-44.15.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP3","name":"tiff","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.9-44.15.2"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libtiff5":"4.0.9-44.15.2","libtiff5-32bit":"4.0.9-44.15.2","tiff":"4.0.9-44.15.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP3","name":"tiff","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.9-44.15.2"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libtiff5":"4.0.9-44.15.2","libtiff5-32bit":"4.0.9-44.15.2","tiff":"4.0.9-44.15.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP3","name":"tiff","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.9-44.15.2"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for tiff fixes the following issues:\n\nThese security issues were fixed:\n\n- CVE-2017-18013: There was a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.  (bsc#1074317)\n- CVE-2018-10963: The TIFFWriteDirectorySec() function in tif_dirwrite.c allowed remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a different vulnerability than CVE-2017-13726.  (bsc#1092949)\n- CVE-2018-7456: Prevent a NULL Pointer dereference in the function TIFFPrintDirectory when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013 (bsc#1082825)\n- CVE-2017-11613: Prevent denial of service in the TIFFOpen function. During the TIFFOpen process, td_imagelength is not checked. The value of td_imagelength can be directly controlled by an input file. In the ChopUpSingleUncompressedStrip function, the _TIFFCheckMalloc function is called based on td_imagelength. If the value of td_imagelength is set close to the amount of system memory, it will hang the system or trigger the OOM killer (bsc#1082332)\n- CVE-2018-8905: Prevent heap-based buffer overflow in the function LZWDecodeCompat via a crafted TIFF file (bsc#1086408)\n- CVE-2016-8331: Prevent remote code execution because of incorrect handling of TIFF images. A crafted TIFF document could have lead to a type confusion vulnerability resulting in remote code execution. This vulnerability could have been be triggered via a TIFF file delivered to the application using LibTIFF's tag extension functionality (bsc#1007276)\n- CVE-2016-3632: The _TIFFVGetField function allowed remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted TIFF image (bsc#974621)\n","id":"SUSE-SU-2018:1826-1","modified":"2018-06-27T10:45:25Z","published":"2018-06-27T10:45:25Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20181826-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1007276"},{"type":"REPORT","url":"https://bugzilla.suse.com/1074317"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082332"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082825"},{"type":"REPORT","url":"https://bugzilla.suse.com/1086408"},{"type":"REPORT","url":"https://bugzilla.suse.com/1092949"},{"type":"REPORT","url":"https://bugzilla.suse.com/974621"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-3632"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-8331"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-11613"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13726"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-18013"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-10963"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-7456"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8905"}],"related":["CVE-2016-3632","CVE-2016-8331","CVE-2017-11613","CVE-2017-13726","CVE-2017-18013","CVE-2018-10963","CVE-2018-7456","CVE-2018-8905"],"summary":"Security update for tiff","upstream":["CVE-2016-3632","CVE-2016-8331","CVE-2017-11613","CVE-2017-13726","CVE-2017-18013","CVE-2018-10963","CVE-2018-7456","CVE-2018-8905"]}