RHSA-2023:5353: Moderate: libtiff security update
Moderate: libtiff security update
Other sources
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.Security Fix(es): libtiff: out-of-bounds write in extractContigSamplesShifted16bits() in tools/tiffcrop.c (CVE-2023-0800) libtiff: out-of-bounds write in TIFFmemcpy() in libtiff/tifunix.c when called by functions in tools/tiffcrop.c (CVE-2023-0801) libtiff: out-of-bounds write in extractContigSamplesShifted32bits() in tools/tiffcrop.c (CVE-2023-0802) libtiff: out-of-bounds write in extractContigSamplesShifted16bits() in tools/tiffcrop.c (CVE-2023-0803) libtiff: out-of-bounds write in extractContigSamplesShifted24bits() in tools/tiffcrop.c (CVE-2023-0804) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:5353?
The severity of RHSA-2023:5353 is moderate.
How do I fix RHSA-2023:5353?
To fix RHSA-2023:5353, update the libtiff package to version 4.0.9-29.el8_8 or later.
Which software is affected by RHSA-2023:5353?
The Red Hat CodeReady Linux Builder for ARM 64, Red Hat Enterprise Linux for x86_64, and other related products and packages are affected by RHSA-2023:5353.
Where can I find more information about RHSA-2023:5353?
You can find more information about RHSA-2023:5353 on the Red Hat Security Advisory page and the associated bugzilla reports (2170167 and 2170172).