compat-libtiff3-3.9.4-16.el8_10

エラータID: AXSA:2026-1400:02

Release date: 
Friday, July 31, 2026 - 15:15
Subject: 
compat-libtiff3-3.9.4-16.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff.

Security Fix(es):

* libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-12912
A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. compat-libtiff3-3.9.4-16.el8_10.src.rpm
    MD5: 36b9e5a77c16fd25f727c72a7e329634
    SHA-256: a9951cc520af20b64e4f2d0af804135002c616d746a329fccaa82f775dab2c56
    Size: 1.41 MB

Asianux Server 8 for x86_64
  1. compat-libtiff3-3.9.4-16.el8_10.i686.rpm
    MD5: 677daf60347adf168be565a082b36b3c
    SHA-256: e60361cdb3ffa6ff9cb8b74e0b29db964ccfae858bac3b657602f5b6c92a50df
    Size: 150.50 kB
  2. compat-libtiff3-3.9.4-16.el8_10.x86_64.rpm
    MD5: b3d2f4d2cefa23cb7295cef4a9265910
    SHA-256: a2cb645d6564d7bdabe368adf4d162a053a27d42777da32b8a44840f22d198ff
    Size: 143.08 kB