Bug 1205422 - (CVE-2022-3570) VUL-0: CVE-2022-3570: tiff: libtiff: heap buffer overflows in tiffcrop.c
(CVE-2022-3570)
VUL-0: CVE-2022-3570: tiff: libtiff: heap buffer overflows in tiffcrop.c
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Michael Vetter
Security Team bot
https://smash.suse.de/issue/346028/
CVSSv3.1:SUSE:CVE-2022-3570:5.5:(AV:L...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-11-15 08:47 UTC by Stoyan Manolov
Modified: 2023-01-10 20:35 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Michael Vetter 2022-11-15 14:13:35 UTC
The fix for this seems to be exactly the same as for bsc#1204642 - (CVE-2022-3598).

So https://build.opensuse.org/request/show/1035628 with the tiff-CVE-2022-3598.patch should fix this for Factory.

For SLE12/15 the fix is not as easy since a lot of code changed.
I will later write my ideas about that in bsc#1204642.

Should the Factory patch be renamed to include both CVE names?
Comment 2 Michael Vetter 2022-11-15 15:57:45 UTC
I have the fixes for CVE-2022-3597 [bsc#1204641] CVE-2022-3626 [bsc#1204644] CVE-2022-3627 [bsc#1204645] CVE-2022-3599 [bsc#1204643] and CVE-2022-3970 [bsc#1205392] in my for SLE12 and SLE15 at https://build.suse.de/project/show/home:mvetter:bv.
All of them are already submitted to Factory.

I am/was still working on CVE-2022-3598 [bsc#1204642] which is a little harder since a lot of code changes happened. I will comment on this bug with more details.

Today I also received CVE-2022-3570 [bsc#1205422] which looks like the same as CVE-2022-3598.

I will be on vacation and will try to find someone who can work on the last remaining CVE and then make a submission. In case any of the fixed bugs are urgent we could also do a submssion already from my home:mvetter:bv to SLE12/SLE15.
Comment 6 Swamp Workflow Management 2022-12-13 08:27:56 UTC
SUSE-SU-2022:4411-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1204642,1205422
CVE References: CVE-2022-3570,CVE-2022-3598
JIRA References: 
Sources used:
openSUSE Leap Micro 5.3 (src):    tiff-4.0.9-150000.45.22.1
openSUSE Leap Micro 5.2 (src):    tiff-4.0.9-150000.45.22.1
openSUSE Leap 15.4 (src):    tiff-4.0.9-150000.45.22.1
openSUSE Leap 15.3 (src):    tiff-4.0.9-150000.45.22.1
SUSE Manager Server 4.1 (src):    tiff-4.0.9-150000.45.22.1
SUSE Manager Retail Branch Server 4.1 (src):    tiff-4.0.9-150000.45.22.1
SUSE Manager Proxy 4.1 (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Server for SAP 15 (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Server 15-SP2-BCL (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Server 15-LTSS (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Module for Basesystem 15-SP4 (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Micro 5.3 (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise Micro 5.2 (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    tiff-4.0.9-150000.45.22.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    tiff-4.0.9-150000.45.22.1
SUSE Enterprise Storage 7 (src):    tiff-4.0.9-150000.45.22.1
SUSE Enterprise Storage 6 (src):    tiff-4.0.9-150000.45.22.1
SUSE CaaS Platform 4.0 (src):    tiff-4.0.9-150000.45.22.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Swamp Workflow Management 2023-01-10 17:21:38 UTC
SUSE-SU-2023:0060-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1204642,1205422
CVE References: CVE-2022-3570,CVE-2022-3598
JIRA References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    tiff-4.0.9-44.62.1
SUSE Linux Enterprise Server 12-SP5 (src):    tiff-4.0.9-44.62.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.