libtiff-4.0.3-35.0.5.el7.AXS7

エラータID: AXSA:2025-10952:04

Release date: 
Tuesday, October 14, 2025 - 09:48
Subject: 
libtiff-4.0.3-35.0.5.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

The libtiff package contains a library of functions for manipulating
TIFF (Tagged Image File Format) image format files. TIFF is a widely
used file format for bitmapped images. TIFF files usually end in the
.tif extension and they are often quite large.

The libtiff package should be installed if you need to manipulate TIFF
format image files.

Security Fix(es):

* CVE-2017-5225: fix heap buffer overflow in tools/tiffcp by restricting
BitsPerSample values

CVE(s):
CVE-2017-5225
LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample value.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

Asianux Server 7 for x86_64
  1. libtiff-4.0.3-35.0.5.el7.AXS7.i686.rpm
    MD5: 9439e0d94537d816c51f3d02cfa805af
    SHA-256: ede5fe51d73196a960ae3b9f2800a70047b0bfe65e79a085dca390bbf7443b08
    Size: 176.48 kB
  2. libtiff-4.0.3-35.0.5.el7.AXS7.x86_64.rpm
    MD5: d133fbfc30b715da6612d69f0e7788ae
    SHA-256: 3f56fc3a8e9dcb3bfdb730ad183c274a7275761f1f1efc7e0d14aae5641ae1d3
    Size: 173.50 kB
  3. libtiff-devel-4.0.3-35.0.5.el7.AXS7.i686.rpm
    MD5: 93f11e8e6b8cf69c890622cd168e555d
    SHA-256: b2c5ded02952bf655170c91e95c1854b26d6d4f1669c047dffba55a086050886
    Size: 475.07 kB
  4. libtiff-devel-4.0.3-35.0.5.el7.AXS7.x86_64.rpm
    MD5: af87c1567e584a934e2898ac8b4f927d
    SHA-256: 60b92561219df912e02f565fdbc52cc2c7d99e1701a402f8969ed8383a8f8286
    Size: 475.04 kB