Security update for tiff

SUSE Security Update: Security update for tiff
Announcement ID: SUSE-SU-2012:0525-1
Rating: moderate
References: #753362
Affected Products:
  • SUSE Linux Enterprise Server 10 SP4
  • SUSE Linux Enterprise Desktop 10 SP4
  • SLE SDK 10 SP4

  • An update that contains security fixes can now be installed.

    Description:


    This update of tiff fixes an issue where specially crafted
    tiff files could trigger an integer overflow which leads
    to a heap-based buffer overflow (CVE-2012-1173).

    Package List:

    • SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x x86_64):
    • libtiff-3.8.2-5.26.1
    • libtiff-devel-3.8.2-5.26.1
    • tiff-3.8.2-5.26.1
    • SUSE Linux Enterprise Server 10 SP4 (s390x x86_64):
    • libtiff-32bit-3.8.2-5.26.1
    • libtiff-devel-32bit-3.8.2-5.26.1
    • SUSE Linux Enterprise Server 10 SP4 (ia64):
    • libtiff-x86-3.8.2-5.26.1
    • SUSE Linux Enterprise Server 10 SP4 (ppc):
    • libtiff-64bit-3.8.2-5.26.1
    • libtiff-devel-64bit-3.8.2-5.26.1
    • SUSE Linux Enterprise Desktop 10 SP4 (i586 x86_64):
    • libtiff-3.8.2-5.26.1
    • libtiff-devel-3.8.2-5.26.1
    • tiff-3.8.2-5.26.1
    • SUSE Linux Enterprise Desktop 10 SP4 (x86_64):
    • libtiff-32bit-3.8.2-5.26.1
    • SLE SDK 10 SP4 (i586 ia64 ppc s390x x86_64):
    • libtiff-devel-3.8.2-5.26.1
    • SLE SDK 10 SP4 (s390x x86_64):
    • libtiff-devel-32bit-3.8.2-5.26.1
    • SLE SDK 10 SP4 (ppc):
    • libtiff-devel-64bit-3.8.2-5.26.1

    References:

    • https://bugzilla.novell.com/753362
    • http://download.suse.com/patch/finder/?keywords=3c1e26e281f6488d70976e6d76893183