{"affected":[{"ecosystem_specific":{"binaries":[{"libtiff5":"4.0.7-43.1","libtiff5-32bit":"4.0.7-43.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP1","name":"tiff","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.7-43.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libtiff5":"4.0.7-43.1","libtiff5-32bit":"4.0.7-43.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP2","name":"tiff","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.7-43.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libtiff5":"4.0.7-43.1","tiff":"4.0.7-43.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2","name":"tiff","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.7-43.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libtiff-devel":"4.0.7-43.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP1","name":"tiff","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.7-43.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libtiff-devel":"4.0.7-43.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP2","name":"tiff","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.7-43.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libtiff5":"4.0.7-43.1","libtiff5-32bit":"4.0.7-43.1","tiff":"4.0.7-43.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP1","name":"tiff","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.7-43.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libtiff5":"4.0.7-43.1","libtiff5-32bit":"4.0.7-43.1","tiff":"4.0.7-43.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP1","name":"tiff","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.7-43.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libtiff5":"4.0.7-43.1","libtiff5-32bit":"4.0.7-43.1","tiff":"4.0.7-43.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP2","name":"tiff","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.7-43.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libtiff5":"4.0.7-43.1","libtiff5-32bit":"4.0.7-43.1","tiff":"4.0.7-43.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP2","name":"tiff","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.7-43.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nThis update for tiff fixes the following issues:\n\nSecurity issues fixed:\n- CVE-2016-10272: LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based\n  buffer overflow) or possibly have unspecified other impact via a crafted TIFF image, related to\n  'WRITE of size 2048' and libtiff/tif_next.c:64:9 (bsc#1031247).\n- CVE-2016-10271: tools/tiffcrop.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of\n  service (heap-based buffer over-read and buffer overflow) or possibly have unspecified other\n  impact via a crafted TIFF image, related to 'READ of size 1' and libtiff/tif_fax3.c:413:13\n  (bsc#1031249).\n- CVE-2016-10270: LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based\n  buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to\n  'READ of size 8' and libtiff/tif_read.c:523:22 (bsc#1031250).\n- CVE-2016-10269: LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based\n  buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to\n  'READ of size 512' and libtiff/tif_unix.c:340:2 (bsc#1031254).\n- CVE-2016-10268: tools/tiffcp.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of\n  service (integer underflow and heap-based buffer under-read) or possibly have unspecified other\n  impact via a crafted TIFF image, related to 'READ of size 78490' and libtiff/tif_unix.c:115:23\n  (bsc#1031255).\n- CVE-2016-10267: LibTIFF 4.0.7 allows remote attackers to cause a denial of service\n  (divide-by-zero error and application crash) via a crafted TIFF image, related to\n  libtiff/tif_ojpeg.c:816:8 (bsc#1031262).\n- CVE-2016-10266: LibTIFF 4.0.7 allows remote attackers to cause a denial of service\n  (divide-by-zero error and application crash) via a crafted TIFF image, related to\n  libtiff/tif_read.c:351:22. (bsc#1031263).\n","id":"SUSE-SU-2017:1044-1","modified":"2017-04-18T09:29:45Z","published":"2017-04-18T09:29:45Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20171044-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1031247"},{"type":"REPORT","url":"https://bugzilla.suse.com/1031249"},{"type":"REPORT","url":"https://bugzilla.suse.com/1031250"},{"type":"REPORT","url":"https://bugzilla.suse.com/1031254"},{"type":"REPORT","url":"https://bugzilla.suse.com/1031255"},{"type":"REPORT","url":"https://bugzilla.suse.com/1031262"},{"type":"REPORT","url":"https://bugzilla.suse.com/1031263"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-10266"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-10267"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-10268"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-10269"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-10270"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-10271"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-10272"}],"related":["CVE-2016-10266","CVE-2016-10267","CVE-2016-10268","CVE-2016-10269","CVE-2016-10270","CVE-2016-10271","CVE-2016-10272"],"summary":"Security update for tiff","upstream":["CVE-2016-10266","CVE-2016-10267","CVE-2016-10268","CVE-2016-10269","CVE-2016-10270","CVE-2016-10271","CVE-2016-10272"]}