Bug 30440

Summary: libtiff new security issue CVE-2022-1056
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Mageia Bug Squad <bugsquad>
Status: RESOLVED DUPLICATE QA Contact: Sec team <security>
Severity: major    
Priority: Normal CC: nicolas.salguero
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA8TOO
Source RPM: libtiff-4.3.0-5.mga9.src.rpm CVE:
Status comment:

Description David Walser 2022-05-16 20:22:59 CEST
SUSE has issued an advisory today (May 16):
https://lists.suse.com/pipermail/sle-security-updates/2022-May/011027.html

Mageia 8 is also affected.
David Walser 2022-05-16 20:23:19 CEST

CC: (none) => nicolas.salguero
Whiteboard: (none) => MGA8TOO

Comment 1 Nicolas Salguero 2022-05-17 09:22:09 CEST
Hi,

According to openSUSE and Debian, the commit that fixes CVE-2022-1056 is https://gitlab.com/libtiff/libtiff/-/commit/232282fd8f9c21eefe8d2d2b96cdbbb172fe7b7c.

The patch from that commit was already added to fix the CVEs from bug 30210.

Best regards,

Nico.
Comment 2 David Walser 2022-05-17 13:03:41 CEST
Thanks.

*** This bug has been marked as a duplicate of bug 30210 ***

Resolution: (none) => DUPLICATE
Status: NEW => RESOLVED