Bug 964225 - (CVE-2015-8782) VUL-1: CVE-2015-8781, CVE-2015-8782, CVE-2015-8783: tiff: out-of-bounds writes for invalid images in tif_libtuv
(CVE-2015-8782)
VUL-1: CVE-2015-8781, CVE-2015-8782, CVE-2015-8783: tiff: out-of-bounds write...
Status: RESOLVED FIXED
: CVE-2015-8781 (view as bug list)
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Normal
: ---
Assigned To: Michael Vetter
Security Team bot
https://smash.suse.de/issue/161257/
maint:released:sle10-sp3:62519 CVSSv2...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2016-01-29 16:37 UTC by Johannes Segitz
Modified: 2018-12-05 07:44 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Johannes Segitz 2016-01-29 16:41:18 UTC
*** Bug 964213 has been marked as a duplicate of this bug. ***
Comment 2 Johannes Segitz 2016-01-29 16:42:22 UTC
CVE-2015-8781, CVE-2015-8782, CVE-2015-8783
Comment 3 Swamp Workflow Management 2016-01-29 23:00:45 UTC
bugbot adjusting priority
Comment 4 Bernhard Wiedemann 2016-02-01 09:00:08 UTC
This is an autogenerated message for OBS integration:
This bug (964225) was mentioned in
https://build.opensuse.org/request/show/357067 Factory / tiff
Comment 6 Bernhard Wiedemann 2016-02-01 10:00:07 UTC
This is an autogenerated message for OBS integration:
This bug (964225) was mentioned in
https://build.opensuse.org/request/show/357081 13.1 / tiff
https://build.opensuse.org/request/show/357082 13.2 / tiff
Comment 8 Swamp Workflow Management 2016-02-05 20:12:21 UTC
SUSE-SU-2016:0353-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 960341,964225
CVE References: CVE-2015-7554,CVE-2015-8781,CVE-2015-8782,CVE-2015-8783
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    tiff-3.8.2-141.163.1
SUSE Linux Enterprise Server 11-SP4 (src):    tiff-3.8.2-141.163.1
SUSE Linux Enterprise Desktop 11-SP4 (src):    tiff-3.8.2-141.163.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    tiff-3.8.2-141.163.1
Comment 9 Swamp Workflow Management 2016-02-10 15:11:44 UTC
openSUSE-SU-2016:0405-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 964225
CVE References: CVE-2015-8781,CVE-2015-8782,CVE-2015-8783
Sources used:
openSUSE 13.2 (src):    tiff-4.0.6-10.20.1
Comment 10 Swamp Workflow Management 2016-02-10 23:12:06 UTC
openSUSE-SU-2016:0414-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 964225
CVE References: CVE-2015-8781,CVE-2015-8782,CVE-2015-8783
Sources used:
openSUSE 13.1 (src):    tiff-4.0.6-8.16.1
Comment 11 Swamp Workflow Management 2016-03-02 15:15:54 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2016-03-16.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/62518
Comment 12 Swamp Workflow Management 2016-07-27 17:10:34 UTC
openSUSE-SU-2016:1889-1: An update that solves 5 vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 964225,984808,984831,984837,984842,987351
CVE References: CVE-2016-5314,CVE-2016-5316,CVE-2016-5317,CVE-2016-5320,CVE-2016-5875
Sources used:
openSUSE 13.2 (src):    tiff-4.0.6-10.26.1
Comment 13 Swamp Workflow Management 2016-09-09 10:11:08 UTC
SUSE-SU-2016:2271-1: An update that fixes 9 vulnerabilities is now available.

Category: security (moderate)
Bug References: 964225,973340,984808,984831,984837,984842,987351
CVE References: CVE-2015-8781,CVE-2015-8782,CVE-2015-8783,CVE-2016-3186,CVE-2016-5314,CVE-2016-5316,CVE-2016-5317,CVE-2016-5320,CVE-2016-5875
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    tiff-4.0.6-26.3
SUSE Linux Enterprise Server 12-SP1 (src):    tiff-4.0.6-26.3
SUSE Linux Enterprise Desktop 12-SP1 (src):    tiff-4.0.6-26.3
Comment 14 Swamp Workflow Management 2016-09-16 13:09:46 UTC
openSUSE-SU-2016:2321-1: An update that fixes 9 vulnerabilities is now available.

Category: security (moderate)
Bug References: 964225,973340,984808,984831,984837,984842,987351
CVE References: CVE-2015-8781,CVE-2015-8782,CVE-2015-8783,CVE-2016-3186,CVE-2016-5314,CVE-2016-5316,CVE-2016-5317,CVE-2016-5320,CVE-2016-5875
Sources used:
openSUSE Leap 42.1 (src):    tiff-4.0.6-6.1