Bugzilla – Bug 1195964
VUL-0: CVE-2022-0561: tiff: Null source pointer passed as an argument to memcpy() within TIFFFetchStripThing() in tif_dirread.c
Last modified: 2022-08-17 14:20:48 UTC
CVE-2022-0561 Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, the fix is available with commit eecb0712. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-0561 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0561 https://gitlab.com/freedesktop-sdk/mirrors/gitlab/libtiff/libtiff/-/commit/eecb0712f4c3a5b449f70c57988260a667ddbdef https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0561.json https://gitlab.com/libtiff/libtiff/-/issues/362
Affected: - SUSE:SLE-11:Update - SUSE:SLE-12:Update - SUSE:SLE-15:Update - openSUSE:Factory
Factory: SR#975780 SLE12: SR#271714 SLE15: SR#271715
This is an autogenerated message for OBS integration: This bug (1195964) was mentioned in https://build.opensuse.org/request/show/975780 Factory / tiff
SUSE-SU-2022:1667-1: An update that fixes 8 vulnerabilities is now available. Category: security (important) Bug References: 1195964,1195965,1197066,1197068,1197072,1197073,1197074,1197631 CVE References: CVE-2022-0561,CVE-2022-0562,CVE-2022-0865,CVE-2022-0891,CVE-2022-0908,CVE-2022-0909,CVE-2022-0924,CVE-2022-1056 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): tiff-4.0.9-44.48.1 SUSE Linux Enterprise Server 12-SP5 (src): tiff-4.0.9-44.48.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:1882-1: An update that fixes 8 vulnerabilities is now available. Category: security (important) Bug References: 1195964,1195965,1197066,1197068,1197072,1197073,1197074,1197631 CVE References: CVE-2022-0561,CVE-2022-0562,CVE-2022-0865,CVE-2022-0891,CVE-2022-0908,CVE-2022-0909,CVE-2022-0924,CVE-2022-1056 JIRA References: Sources used: openSUSE Leap 15.4 (src): tiff-4.0.9-150000.45.8.1 openSUSE Leap 15.3 (src): tiff-4.0.9-150000.45.8.1 SUSE Manager Server 4.1 (src): tiff-4.0.9-150000.45.8.1 SUSE Manager Retail Branch Server 4.1 (src): tiff-4.0.9-150000.45.8.1 SUSE Manager Proxy 4.1 (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Server for SAP 15-SP2 (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Server for SAP 15-SP1 (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Server for SAP 15 (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Server 15-SP2-LTSS (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Server 15-SP2-BCL (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Server 15-LTSS (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Module for Basesystem 15-SP4 (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise Micro 5.2 (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): tiff-4.0.9-150000.45.8.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): tiff-4.0.9-150000.45.8.1 SUSE Enterprise Storage 7 (src): tiff-4.0.9-150000.45.8.1 SUSE Enterprise Storage 6 (src): tiff-4.0.9-150000.45.8.1 SUSE CaaS Platform 4.0 (src): tiff-4.0.9-150000.45.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
I checked again, SUSE:SLE-11:Update/tiff is not affected here. Closing, thanks for your help!