View | Details | Raw Unified | Return to bug 211552 | Differences between
and this patch

Collapse All | Expand All

(-)vuln.xml (+45 lines)
Lines 58-63 Link Here
58
  * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
58
  * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
59
-->
59
-->
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
61
  <vuln vid="496682f2-59af-11e6-a1bc-589cfc0654e1">
62
    <topic> linux-c6-tiff - multiple vulnerabilities </topic>
63
    <affects>
64
      <package>
65
	<name>linux-c6-tiff</name>
66
	<name>linux-c6_64-tiff</name>
67
	<range><lt>3.9.4_1</lt></range>
68
      </package>
69
    </affects>
70
    <description>
71
      <body xmlns="http://www.w3.org/1999/xhtml">
72
	<p>Red Hat reports:</p>
73
	<blockquote cite="https://rhn.redhat.com/errata/RHSA-2016-1547.html">
74
	  <p>Security fixes for tiff</p>
75
		<ul>
76
			<li><p>CVE-2014-9330 libtiff: Out-of-bounds reads followed by a crash in bmp2tiff</p></li>
77
			<li><p>CVE-2014-8127 libtiff: out-of-bounds read with malformed TIFF image in multiple tools</p></li>
78
			<li><p>CVE-2014-8129 libtiff: out-of-bounds read/write with malformed TIFF image in tiff2pdf</p></li>
79
			<li><p>CVE-2014-8130 libtiff: divide by zero in the tiffdither tool</p></li>
80
			<li><p>CVE-2014-9655 libtiff: use of uninitialized memory in putcontig8bitYCbCr21tile and NeXTDecode</p></li>
81
			<li><p>CVE-2015-1547 libtiff: use of uninitialized memory in NeXTDecode</p></li>
82
			<li><p>CVE-2015-7554 libtiff: Invalid-write in _TIFFVGetField() when parsing some extension tags</p></li>
83
			<li><p>CVE-2015-8668 libtiff: OOB read in bmp2tiff</p></li>
84
			<li><p>CVE-2015-8683 libtiff: Out-of-bounds when reading CIE Lab image format files</p></li>
85
			<li><p>CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c</p></li>
86
			<li><p>CVE-2015-8781 CVE-2015-8782 CVE-2015-8783 libtiff: invalid assertion</p></li>
87
			<li><p>CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode()</p></li>
88
			<li><p>CVE-2016-3945 libtiff: out-of-bounds write in the tiff2rgba tool</p></li>
89
			<li><p>CVE-2016-3632 libtiff: out-of-bounds write in _TIFFVGetField function</p></li>
90
			<li><p>CVE-2016-3990 libtiff: out-of-bounds write in horizontalDifference8()</p></li>
91
			<li><p>CVE-2016-3991 libtiff: out-of-bounds write in loadImage() function</p></li>
92
			<li><p>CVE-2016-5320 libtiff: Out-of-bounds write in PixarLogDecode() function in tif_pixarlog.c</p></li>
93
		</ul>
94
	</blockquote>
95
      </body>
96
    </description>
97
    <references>
98
      <url>https://rhn.redhat.com/errata/RHSA-2016-1547.html</url>
99
    </references>
100
    <dates>
101
      <discovery>2016-08-02</discovery>
102
      <entry>2016-08-03</entry>
103
    </dates>
104
  </vuln>
105
61
  <vuln vid="ef0033ad-5823-11e6-80cc-001517f335e2">
106
  <vuln vid="ef0033ad-5823-11e6-80cc-001517f335e2">
62
    <topic>lighttpd - multiple vulnerabilities</topic>
107
    <topic>lighttpd - multiple vulnerabilities</topic>
63
    <affects>
108
    <affects>

Return to bug 211552