Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2022.0410
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2022-0410)
Resumen:The remote host is missing an update for the 'libtiff' package(s) announced via the MGASA-2022-0410 advisory.
Descripción:Summary:
The remote host is missing an update for the 'libtiff' package(s) announced via the MGASA-2022-0410 advisory.

Vulnerability Insight:
There is a double free or corruption in rotateImage() at tiffcrop.c:8839
found in libtiff 4.4.0rc1. (CVE-2022-2519)

A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail
in rotateImage() at tiffcrop.c:8621 that can cause program crash when
reading a crafted input. (CVE-2022-2520)

It was found in libtiff 4.4.0rc1 that there is an invalid pointer free
operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that
can cause a program crash and denial of service while processing crafted
input. (CVE-2022-2521)

Multiple heap buffer overflows in tiffcrop.c utility in libtiff library
Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory
access via crafted TIFF image file which could result into application
crash, potential information disclosure or any other context-dependent
impact. (CVE-2022-3570)

LibTIFF 4.4.0 has an out-of-bounds write in
extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing
attackers to cause a denial-of-service via a crafted tiff file.
(CVE-2022-3598)

Affected Software/OS:
'libtiff' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2022-2519
DSA-5333
https://www.debian.org/security/2023/dsa-5333
https://gitlab.com/libtiff/libtiff/-/issues/423
https://gitlab.com/libtiff/libtiff/-/merge_requests/378
Common Vulnerability Exposure (CVE) ID: CVE-2022-2520
https://gitlab.com/libtiff/libtiff/-/issues/424
Common Vulnerability Exposure (CVE) ID: CVE-2022-2521
https://gitlab.com/libtiff/libtiff/-/issues/422
Common Vulnerability Exposure (CVE) ID: CVE-2022-3570
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3570.json
Debian Security Information: DSA-5333 (Google Search)
https://gitlab.com/libtiff/libtiff/-/commit/bd94a9b383d8755a27b5a1bc27660b8ad10b094c
https://gitlab.com/libtiff/libtiff/-/issues/381
https://gitlab.com/libtiff/libtiff/-/issues/386
https://lists.debian.org/debian-lts-announce/2023/01/msg00018.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-3598
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3598.json
https://gitlab.com/libtiff/libtiff/-/commit/cfbb883bf6ea7bedcb04177cc4e52d304522fdff
https://gitlab.com/libtiff/libtiff/-/issues/435
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.