openSUSE Security Update : tiff (openSUSE-2018-728)

high Nessus Plugin ID 111099

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for tiff fixes the following security issues :

These security issues were fixed :

- CVE-2017-18013: Fixed a NULL pointer dereference in the tif_print.cTIFFPrintDirectory function that could have lead to denial of service (bsc#1074317).

- CVE-2018-10963: Fixed an assertion failure in the TIFFWriteDirectorySec() function in tif_dirwrite.c, which allowed remote attackers to cause a denial of service via a crafted file (bsc#1092949).

- CVE-2018-7456: Prevent a NULL pointer dereference in the function TIFFPrintDirectory when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013 (bsc#1082825).

- CVE-2017-11613: Prevent denial of service in the TIFFOpen function. During the TIFFOpen process, td_imagelength is not checked. The value of td_imagelength can be directly controlled by an input file. In the ChopUpSingleUncompressedStrip function, the
_TIFFCheckMalloc function is called based on td_imagelength. If the value of td_imagelength is set close to the amount of system memory, it will hang the system or trigger the OOM killer (bsc#1082332).

- CVE-2018-8905: Prevent heap-based buffer overflow in the function LZWDecodeCompat via a crafted TIFF file (bsc#1086408).

This update was imported from the SUSE:SLE-15:Update update project.

Solution

Update the affected tiff packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1074317

https://bugzilla.opensuse.org/show_bug.cgi?id=1082332

https://bugzilla.opensuse.org/show_bug.cgi?id=1082825

https://bugzilla.opensuse.org/show_bug.cgi?id=1086408

https://bugzilla.opensuse.org/show_bug.cgi?id=1092949

Plugin Details

Severity: High

ID: 111099

File Name: openSUSE-2018-728.nasl

Version: 1.4

Type: local

Agent: unix

Published: 7/16/2018

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:libtiff-devel, p-cpe:/a:novell:opensuse:libtiff-devel-32bit, p-cpe:/a:novell:opensuse:libtiff5, p-cpe:/a:novell:opensuse:libtiff5-32bit, p-cpe:/a:novell:opensuse:libtiff5-32bit-debuginfo, p-cpe:/a:novell:opensuse:libtiff5-debuginfo, p-cpe:/a:novell:opensuse:tiff, p-cpe:/a:novell:opensuse:tiff-debuginfo, p-cpe:/a:novell:opensuse:tiff-debugsource, cpe:/o:novell:opensuse:15.0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 7/13/2018

Reference Information

CVE: CVE-2017-11613, CVE-2017-18013, CVE-2018-10963, CVE-2018-7456, CVE-2018-8905