Lucene search

K
mageiaGentoo FoundationMGASA-2021-0098
HistoryMar 04, 2021 - 3:26 p.m.

Updated libtiff packages fix security vulnerabilities

2021-03-0415:26:19
Gentoo Foundation
advisories.mageia.org
29
libtiff
security
vulnerabilities
integer overflow
heap-based buffer overflow
buffer overflow
memory allocation failure
denial of service

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.006

Percentile

79.5%

The updated libtiff packages fix security vulnerabilities: - Integer overflow in tif_getimage.c (CVE-2020-35523). - Heap-based buffer overflow in TIFF2PDF tool (CVE-2020-35524). - Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the β€œTIFFVGetField” funtion in the component β€˜libtiff/tif_dir.c’. (CVE-2020-19143) - Memory allocation failure in tiff2rgba (CVE-2020-35521) - Memory allocation failure in tiff2rgba (CVE-2020-35522)

OSVersionArchitecturePackageVersionFilename
Mageia7noarchlibtiff<Β 4.2.0-1libtiff-4.2.0-1.mga7

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.006

Percentile

79.5%