AXSA:2019-4125:01

Release date: 
Tuesday, August 20, 2019 - 02:01
Subject: 
libtiff-4.0.3-32.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.

Security Fix(es):

* libtiff: buffer overflow in gif2tiff (CVE-2016-3186)

* libtiff: Heap-based buffer overflow in the cpSeparateBufToContigBuf function resulting in a denial of service or possibly code execution (CVE-2018-12900)

* libtiff: Out-of-bounds write in tif_jbig.c (CVE-2018-18557)

* libtiff: NULL pointer dereference in tif_print.c:TIFFPrintDirectory() causes a denial of service (CVE-2018-7456)

* libtiff: heap-based buffer overflow in tif_lzw.c:LZWDecodeCompat() allows for denial of service (CVE-2018-8905)

* libtiff: heap-based buffer over-read in TIFFWriteScanline function in tif_write.c (CVE-2018-10779)

* libtiff: reachable assertion in TIFFWriteDirectorySec function in tif_dirwrite.c (CVE-2018-10963)

* libtiff: Integer overflow in multiply_ms in tools/ppm2tiff.c (CVE-2018-17100)

* libtiff: Two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c (CVE-2018-17101)

* libtiff: tiff2bw tool failed memory allocation leads to crash (CVE-2018-18661)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2016-3186
Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.
CVE-2018-10779
TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.
CVE-2018-10963
The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a different vulnerability than CVE-2017-13726.
CVE-2018-12900
Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via a crafted TIFF file.
CVE-2018-17100
An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) or possibly have unspecified other impact via a crafted image file.
CVE-2018-17101
An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.
CVE-2018-18557
LibTIFF 4.0.9 (with JBIG enabled) decodes arbitrarily-sized JBIG into a buffer, ignoring the buffer size, which leads to a tif_jbig.c JBIGDecode out-of-bounds write.
CVE-2018-18661
An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c.
CVE-2018-7456
A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 4.0.9 when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013. (This affects an earlier part of the TIFFPrintDirectory function that was not addressed by the CVE-2017-18013 patch.)
CVE-2018-8905
In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
1. libtiff-4.0.3-32.el7.src.rpm
md5sum: da8fa39d96f76bd194b73966b83fb77a
sha256sum: 7c96b007b5d2e2cd404c5a23b05341295ed543abb47d45da6599f837ac60ad13
Size: 2,071 Kb

Asianux Server 7.0 for x86_64
1. libtiff-4.0.3-32.el7.x86_64.rpm
md5sum: 7ec36e1818d192985d61b873eaaad683
sha256sum: a4ee12af485157048e94a00533b6fb20411c3db057176eb60d16c92a0a001c71
Size: 170 Kb
2. libtiff-devel-4.0.3-32.el7.x86_64.rpm
md5sum: 93a921a267d448e80b9f3b9099794071
sha256sum: 5565b16782757ad8bceabf45aed29d5164039ca2b9100b5dddcd63e0f6ba97ce
Size: 473 Kb
3. libtiff-4.0.3-32.el7.i686.rpm
md5sum: a1c7d6c6771febb6a80f672a7e526600
sha256sum: cde2164b8ee295d449cdf276ab0f105702444d10ec732eb5cfecbdfb44adfb08
Size: 173 Kb
4. libtiff-devel-4.0.3-32.el7.i686.rpm
md5sum: a4dc3dd5a93fcef50afabf6f4633b315
sha256sum: d8a26a826309feb901ced7f216dc32cd088d3a2d286f0479189bdc2d94b36f09
Size: 473 Kb
Copyright© 2007-2015 Asianux. All rights reserved.