Bug 1204645 (CVE-2022-3627)

Summary: VUL-0: CVE-2022-3627: tiff: out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c
Product: [Novell Products] SUSE Security Incidents Reporter: Alexander Bergmann <abergmann>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: mvetter, postadal, security-team, stoyan.manolov
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/346023/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-3627:6.5:(AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Alexander Bergmann 2022-10-24 09:48:09 UTC
CVE-2022-3627

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in
libtiff/tif_unix.c:346 when called from extractImageSection,
tools/tiffcrop.c:6860, allowing attackers to cause a denial-of-service via a
crafted tiff file. For users that compile libtiff from sources, the fix is
available with commit 236b7191.

Upstream commit:
https://gitlab.com/libtiff/libtiff/-/commit/236b7191f04c60d09ee836ae13b50f812c841047

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3627
https://www.cve.org/CVERecord?id=CVE-2022-3627
https://gitlab.com/libtiff/libtiff/-/issues/411
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3627.json
Comment 2 OBSbugzilla Bot 2022-11-13 23:35:10 UTC
This is an autogenerated message for OBS integration:
This bug (1204645) was mentioned in
https://build.opensuse.org/request/show/1035543 Factory / tiff
Comment 3 OBSbugzilla Bot 2022-11-14 13:35:10 UTC
This is an autogenerated message for OBS integration:
This bug (1204645) was mentioned in
https://build.opensuse.org/request/show/1035628 Factory / tiff
Comment 4 Michael Vetter 2022-11-15 15:58:55 UTC
I have the fixes for CVE-2022-3597 [bsc#1204641] CVE-2022-3626 [bsc#1204644] CVE-2022-3627 [bsc#1204645] CVE-2022-3599 [bsc#1204643] and CVE-2022-3970 [bsc#1205392] in my for SLE12 and SLE15 at https://build.suse.de/project/show/home:mvetter:bv.
All of them are already submitted to Factory.

I am/was still working on CVE-2022-3598 [bsc#1204642] which is a little harder since a lot of code changes happened. I will comment on this bug with more details.

Today I also received CVE-2022-3570 [bsc#1205422] which looks like the same as CVE-2022-3598.

I will be on vacation and will try to find someone who can work on the last remaining CVE and then make a submission. In case any of the fixed bugs are urgent we could also do a submssion already from my home:mvetter:bv to SLE12/SLE15.
Comment 7 Swamp Workflow Management 2022-11-28 14:22:22 UTC
SUSE-SU-2022:4248-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1204641,1204643,1204644,1204645,1205392
CVE References: CVE-2022-3597,CVE-2022-3599,CVE-2022-3626,CVE-2022-3627,CVE-2022-3970
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    tiff-4.0.9-44.59.1
SUSE OpenStack Cloud 9 (src):    tiff-4.0.9-44.59.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    tiff-4.0.9-44.59.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    tiff-4.0.9-44.59.1
SUSE Linux Enterprise Server 12-SP5 (src):    tiff-4.0.9-44.59.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    tiff-4.0.9-44.59.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    tiff-4.0.9-44.59.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    tiff-4.0.9-44.59.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2022-11-28 20:28:07 UTC
SUSE-SU-2022:4259-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1204641,1204643,1204644,1204645,1205392
CVE References: CVE-2022-3597,CVE-2022-3599,CVE-2022-3626,CVE-2022-3627,CVE-2022-3970
JIRA References: 
Sources used:
openSUSE Leap Micro 5.3 (src):    tiff-4.0.9-150000.45.19.1
openSUSE Leap Micro 5.2 (src):    tiff-4.0.9-150000.45.19.1
openSUSE Leap 15.4 (src):    tiff-4.0.9-150000.45.19.1
openSUSE Leap 15.3 (src):    tiff-4.0.9-150000.45.19.1
SUSE Manager Server 4.1 (src):    tiff-4.0.9-150000.45.19.1
SUSE Manager Retail Branch Server 4.1 (src):    tiff-4.0.9-150000.45.19.1
SUSE Manager Proxy 4.1 (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server for SAP 15 (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server 15-SP2-BCL (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Server 15-LTSS (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Module for Basesystem 15-SP4 (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Micro 5.3 (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise Micro 5.2 (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    tiff-4.0.9-150000.45.19.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    tiff-4.0.9-150000.45.19.1
SUSE Enterprise Storage 7 (src):    tiff-4.0.9-150000.45.19.1
SUSE Enterprise Storage 6 (src):    tiff-4.0.9-150000.45.19.1
SUSE CaaS Platform 4.0 (src):    tiff-4.0.9-150000.45.19.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Marcus Meissner 2023-02-01 14:55:51 UTC
please reassign fixed bugs to security-team@suse.de, we will close them.

all is done here