Bug 1212883 (CVE-2023-25433)

Summary: VUL-0: CVE-2023-25433: tiff: Buffer Overflow via /libtiff/tools/tiffcrop.c
Product: [Novell Products] SUSE Security Incidents Reporter: Robert Frohl <rfrohl>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: security-team
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/370924/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Robert Frohl 2023-06-30 08:05:30 UTC
CVE-2023-25433

libtiff 4.5.0 is vulnerable to Buffer Overflow via
/libtiff/tools/tiffcrop.c:8499. Incorrect updating of buffer size after
rotateImage() in tiffcrop cause heap-buffer-overflow and SEGV.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-25433
https://bugzilla.redhat.com/show_bug.cgi?id=2218744
https://www.cve.org/CVERecord?id=CVE-2023-25433
https://gitlab.com/libtiff/libtiff/-/issues/520
https://gitlab.com/libtiff/libtiff/-/merge_requests/467
Comment 1 Robert Frohl 2023-06-30 08:34:56 UTC
I believe fixed by tiff-CVE-2023-0795,CVE-2023-0796,CVE-2023-0797,CVE-2023-0798,CVE-2023-0799.patch

tracking SLE15, SLE12 and ALP as already fixed.
Comment 5 Michael Vetter 2023-10-31 09:48:40 UTC
SR accepted
Comment 6 Maintenance Automation 2023-11-06 12:30:21 UTC
SUSE-SU-2023:4371-1: An update that solves nine vulnerabilities can now be installed.

Category: security (moderate)
Bug References: 1212535, 1212881, 1212883, 1212888, 1213273, 1213274, 1213589, 1213590, 1214574
CVE References: CVE-2020-18768, CVE-2023-25433, CVE-2023-26966, CVE-2023-2908, CVE-2023-3316, CVE-2023-3576, CVE-2023-3618, CVE-2023-38288, CVE-2023-38289
Sources used:
SUSE Linux Enterprise Software Development Kit 12 SP5 (src): tiff-4.0.9-44.71.1
SUSE Linux Enterprise High Performance Computing 12 SP5 (src): tiff-4.0.9-44.71.1
SUSE Linux Enterprise Server 12 SP5 (src): tiff-4.0.9-44.71.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): tiff-4.0.9-44.71.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Maintenance Automation 2023-11-06 12:30:24 UTC
SUSE-SU-2023:4370-1: An update that solves nine vulnerabilities can now be installed.

Category: security (moderate)
Bug References: 1212535, 1212881, 1212883, 1212888, 1213273, 1213274, 1213589, 1213590, 1214574
CVE References: CVE-2020-18768, CVE-2023-25433, CVE-2023-26966, CVE-2023-2908, CVE-2023-3316, CVE-2023-3576, CVE-2023-3618, CVE-2023-38288, CVE-2023-38289
Sources used:
SUSE Linux Enterprise Micro 5.2 (src): tiff-4.0.9-150000.45.32.1
SUSE Linux Enterprise Micro for Rancher 5.2 (src): tiff-4.0.9-150000.45.32.1
openSUSE Leap Micro 5.3 (src): tiff-4.0.9-150000.45.32.1
openSUSE Leap Micro 5.4 (src): tiff-4.0.9-150000.45.32.1
openSUSE Leap 15.4 (src): tiff-4.0.9-150000.45.32.1
openSUSE Leap 15.5 (src): tiff-4.0.9-150000.45.32.1
SUSE Linux Enterprise Micro for Rancher 5.3 (src): tiff-4.0.9-150000.45.32.1
SUSE Linux Enterprise Micro 5.3 (src): tiff-4.0.9-150000.45.32.1
SUSE Linux Enterprise Micro for Rancher 5.4 (src): tiff-4.0.9-150000.45.32.1
SUSE Linux Enterprise Micro 5.4 (src): tiff-4.0.9-150000.45.32.1
SUSE Linux Enterprise Micro 5.5 (src): tiff-4.0.9-150000.45.32.1
Basesystem Module 15-SP4 (src): tiff-4.0.9-150000.45.32.1
Basesystem Module 15-SP5 (src): tiff-4.0.9-150000.45.32.1
SUSE Package Hub 15 15-SP4 (src): tiff-4.0.9-150000.45.32.1
SUSE Package Hub 15 15-SP5 (src): tiff-4.0.9-150000.45.32.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Gabriele Sonnu 2024-06-07 13:32:33 UTC
All done, closing.