Update Info

SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-4869


Security update for tiff


Type: security
Severity: important
Issued: 2023-12-14
Description:
This update for tiff fixes the following issues:

- CVE-2023-2731: Fix null pointer deference in LZWDecode() (bsc#1211478).
- CVE-2023-1916: Fix out-of-bounds read in extractImageSection() (bsc#1210231).
- CVE-2023-26965: Fix heap-based use after free in loadImage() (bsc#1212398).
- CVE-2022-40090: Fix infinite loop in TIFFReadDirectory() (bsc#1214680).


              

Packages


  • tiff-4.0.9-150000.45.35.1