• [SECURITY] [DSA 5567-1] tiff security update

    From Aron Xu@21:1/5 to All on Mon Nov 27 06:10:01 2023
    Hash: SHA256

    - - ------------------------------------------------------------------------- Debian Security Advisory DSA-5567-1 security@debian.org https://www.debian.org/security/ Aron Xu November 27, 2023 https://www.debian.org/security/faq
    - - -------------------------------------------------------------------------

    Package : tiff
    CVE ID : CVE-2023-3576 CVE-2023-40745 CVE-2023-41175
    Debian Bug :

    Brief introduction

    Multiple buffer overflows and memory leak issues have been found in tiff,
    the Tag Image File Format (TIFF) library and tools, which may cause denial
    of service when processing a crafted TIFF image.

    For the oldstable distribution (bullseye), these problems have been fixed
    in version 4.2.0-1+deb11u5.

    For the stable distribution (bookworm), these problems have been fixed in version 4.5.0-6+deb12u1.

    We recommend that you upgrade your tiff packages.

    For the detailed security status of tiff please refer to
    its security tracker page at:

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org

    iQEzBAEBCAAdFiEEhhz+aYQl/Bp4OTA7O1LKKgqv2VQFAmVkI0cACgkQO1LKKgqv 2VT46QgAvtYySLyFvbEsmMlcHIFWXRtkqO2cxtsb7F0NDN8vl2yATpPN8ZWeEmFx ES3DEpRJkAmZ9Of+87a06r4tdFAQlg/uqwMMO4WbdihUlzgnsRLXKUSUqHMFv3Wr 9nvckp6OCwztPUb0G+bpAn+dJHqs6iF3q6ukwWcW0cprLQzigUMmxTnvWt4bc4eT 1nfWRLWkwVObl488Lq94zawtB3NZoQaNvQDMHxVZ7VPsQvDSrKAT71/TnzFUpXJl UePBCKUmK1Q0a6akxBpoNAr6ujdrWcCPDMNl7+jBJE3AwoMPZptTlIsqKTYTT4qr td80YDYxVScgc+t2GrO1PgzM12/Mqg==
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)