openSUSE Security Update: Security update for tiff ______________________________________________________________________________ Announcement ID: openSUSE-SU-2015:1213-1 Rating: moderate References: #914890 #916925 #916927 Cross-References: CVE-2014-8127 CVE-2014-8128 CVE-2014-8129 CVE-2014-8130 CVE-2014-9655 CVE-2015-1547 Affected Products: openSUSE 13.2 openSUSE 13.1 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: tiff was updated to version 4.0.4 to fix six security issues found by fuzzing initiatives. These security issues were fixed: - CVE-2014-8127: Out-of-bounds write (bnc#914890). - CVE-2014-9655: Access of uninitialized memory (bnc#916927). - CVE-2014-8130: Out-of-bounds write (bnc#914890). - CVE-2015-1547: Use of uninitialized memory in NeXTDecode (bnc#916925). - CVE-2014-8129: Out-of-bounds write (bnc#914890). - CVE-2014-8128: Out-of-bounds write (bnc#914890). Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.2: zypper in -t patch openSUSE-2015-476=1 - openSUSE 13.1: zypper in -t patch openSUSE-2015-476=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.2 (i586 x86_64): libtiff-devel-4.0.4-10.10.1 libtiff5-4.0.4-10.10.1 libtiff5-debuginfo-4.0.4-10.10.1 tiff-4.0.4-10.10.1 tiff-debuginfo-4.0.4-10.10.1 tiff-debugsource-4.0.4-10.10.1 - openSUSE 13.2 (x86_64): libtiff-devel-32bit-4.0.4-10.10.1 libtiff5-32bit-4.0.4-10.10.1 libtiff5-debuginfo-32bit-4.0.4-10.10.1 - openSUSE 13.1 (i586 x86_64): libtiff-devel-4.0.4-8.10.1 libtiff5-4.0.4-8.10.1 libtiff5-debuginfo-4.0.4-8.10.1 tiff-4.0.4-8.10.1 tiff-debuginfo-4.0.4-8.10.1 tiff-debugsource-4.0.4-8.10.1 - openSUSE 13.1 (x86_64): libtiff-devel-32bit-4.0.4-8.10.1 libtiff5-32bit-4.0.4-8.10.1 libtiff5-debuginfo-32bit-4.0.4-8.10.1 References: https://www.suse.com/security/cve/CVE-2014-8127.html https://www.suse.com/security/cve/CVE-2014-8128.html https://www.suse.com/security/cve/CVE-2014-8129.html https://www.suse.com/security/cve/CVE-2014-8130.html https://www.suse.com/security/cve/CVE-2014-9655.html https://www.suse.com/security/cve/CVE-2015-1547.html https://bugzilla.suse.com/914890 https://bugzilla.suse.com/916925 https://bugzilla.suse.com/916927