[CLSA-2025:1745271345] libtiff: Fix of 3 CVEs
Type:
security
Severity:
Moderate
Release date:
2025-04-21 21:35:50 UTC
Description:
- CVE-2023-3316: avoid NULL pointer dereference in TIFFClose() when output file fails to open due to invalid path or permissions - CVE-2023-3618: handle errors from writeSelections() to prevent buffer overflow in Fax3Encode() and potential DoS - CVE-2023-3576: resolve memory leak in tiffcrop.c to prevent potential DoS via crafted TIFF file
Updated packages:
  • libtiff-4.4.0-8.el9_2.tuxcare.els2.i686.rpm
    sha:fedfefb5edbab010946c2b8e0d5f03344d5178a1b1393c6d286a5a86499d4607
  • libtiff-4.4.0-8.el9_2.tuxcare.els2.x86_64.rpm
    sha:e47a09c4fce3019b5190d9e8eb9e2bf33d9a9c1c5b78dc0f403e263d615cb7dd
  • libtiff-devel-4.4.0-8.el9_2.tuxcare.els2.i686.rpm
    sha:66136a6394627632bd1bed42fa67eb16487f85819bd706d8a28b9ebd4521b2ec
  • libtiff-devel-4.4.0-8.el9_2.tuxcare.els2.x86_64.rpm
    sha:1fc53c85bdc925e02e1c86e9612ab4451b0a5e0e3bcd42e8d8b1354421797948
  • libtiff-static-4.4.0-8.el9_2.tuxcare.els2.x86_64.rpm
    sha:fd367d288f6e8c49ce1c5e8d1390f436b499eb9e21f63da94342588400a766a1
  • libtiff-tools-4.4.0-8.el9_2.tuxcare.els2.x86_64.rpm
    sha:32657f72d486de24f116716b09e52a5aaaf9b9ee77c69d390bddd1c9119a2ee6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.