[go: up one dir, main page]

Bug 1011842 (CVE-2016-9537) - VUL-0: CVE-2016-9537: tiff: Out-of-bounds write vulnerabilities in tools/tiffcrop.c
Summary: VUL-0: CVE-2016-9537: tiff: Out-of-bounds write vulnerabilities in tools/tiff...
Status: RESOLVED FIXED
Alias: CVE-2016-9537
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/176695/
Whiteboard: CVSSv2:RedHat:CVE-2016-9537:5.1:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-11-23 11:23 UTC by Alexander Bergmann
Modified: 2018-11-30 12:36 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2016-11-23 11:23:10 UTC
rh#1397760

It was found that tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers.

Upstream patch:
https://github.com/vadz/libtiff/commit/83a4b92815ea04969d494416eaae3d4c6b338e4a#diff-c8b4b355f9b5c06d585b23138e1c185f

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1397760
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9537
http://www.cvedetails.com/cve/CVE-2016-9537/
Comment 1 Alexander Bergmann 2016-11-23 14:44:34 UTC
tools/tiffcrop.c is only available in SLE-12. All other codestreams seams to be not affected.
Comment 2 Swamp Workflow Management 2016-11-23 23:01:50 UTC
bugbot adjusting priority
Comment 3 Petr Gajdos 2018-04-25 13:31:46 UTC
The fix is already in 12/tiff as far as I can see. Suggest to close as fixed.
Comment 4 Marcus Meissner 2018-11-30 12:36:13 UTC
already fixed