openSUSE Security Update: Security update for tiff ______________________________________________________________________________
Announcement ID: openSUSE-SU-2015:1213-1 Rating: moderate References: #914890 #916925 #916927 Cross-References: CVE-2014-8127 CVE-2014-8128 CVE-2014-8129 CVE-2014-8130 CVE-2014-9655 CVE-2015-1547
Affected Products: openSUSE 13.2 openSUSE 13.1 ______________________________________________________________________________
An update that fixes 6 vulnerabilities is now available.
Description:
tiff was updated to version 4.0.4 to fix six security issues found by fuzzing initiatives.
These security issues were fixed: - CVE-2014-8127: Out-of-bounds write (bnc#914890). - CVE-2014-9655: Access of uninitialized memory (bnc#916927). - CVE-2014-8130: Out-of-bounds write (bnc#914890). - CVE-2015-1547: Use of uninitialized memory in NeXTDecode (bnc#916925). - CVE-2014-8129: Out-of-bounds write (bnc#914890). - CVE-2014-8128: Out-of-bounds write (bnc#914890).
Patch Instructions:
To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product:
- openSUSE 13.2:
zypper in -t patch openSUSE-2015-476=1
- openSUSE 13.1:
zypper in -t patch openSUSE-2015-476=1
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 13.2 (i586 x86_64):
libtiff-devel-4.0.4-10.10.1 libtiff5-4.0.4-10.10.1 libtiff5-debuginfo-4.0.4-10.10.1 tiff-4.0.4-10.10.1 tiff-debuginfo-4.0.4-10.10.1 tiff-debugsource-4.0.4-10.10.1
- openSUSE 13.2 (x86_64):
libtiff-devel-32bit-4.0.4-10.10.1 libtiff5-32bit-4.0.4-10.10.1 libtiff5-debuginfo-32bit-4.0.4-10.10.1
- openSUSE 13.1 (i586 x86_64):
libtiff-devel-4.0.4-8.10.1 libtiff5-4.0.4-8.10.1 libtiff5-debuginfo-4.0.4-8.10.1 tiff-4.0.4-8.10.1 tiff-debuginfo-4.0.4-8.10.1 tiff-debugsource-4.0.4-8.10.1
- openSUSE 13.1 (x86_64):
libtiff-devel-32bit-4.0.4-8.10.1 libtiff5-32bit-4.0.4-8.10.1 libtiff5-debuginfo-32bit-4.0.4-8.10.1
References:
https://www.suse.com/security/cve/CVE-2014-8127.html https://www.suse.com/security/cve/CVE-2014-8128.html https://www.suse.com/security/cve/CVE-2014-8129.html https://www.suse.com/security/cve/CVE-2014-8130.html https://www.suse.com/security/cve/CVE-2014-9655.html https://www.suse.com/security/cve/CVE-2015-1547.html https://bugzilla.suse.com/914890 https://bugzilla.suse.com/916925 https://bugzilla.suse.com/916927