Bug 30440 - libtiff new security issue CVE-2022-1056
Summary: libtiff new security issue CVE-2022-1056
Status: RESOLVED DUPLICATE of bug 30210
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact: Sec team
URL:
Whiteboard: MGA8TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2022-05-16 20:22 CEST by David Walser
Modified: 2022-05-17 13:03 CEST (History)
1 user (show)

See Also:
Source RPM: libtiff-4.3.0-5.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-05-16 20:22:59 CEST
SUSE has issued an advisory today (May 16):
https://lists.suse.com/pipermail/sle-security-updates/2022-May/011027.html

Mageia 8 is also affected.
David Walser 2022-05-16 20:23:19 CEST

CC: (none) => nicolas.salguero
Whiteboard: (none) => MGA8TOO

Comment 1 Nicolas Salguero 2022-05-17 09:22:09 CEST
Hi,

According to openSUSE and Debian, the commit that fixes CVE-2022-1056 is https://gitlab.com/libtiff/libtiff/-/commit/232282fd8f9c21eefe8d2d2b96cdbbb172fe7b7c.

The patch from that commit was already added to fix the CVEs from bug 30210.

Best regards,

Nico.
Comment 2 David Walser 2022-05-17 13:03:41 CEST
Thanks.

*** This bug has been marked as a duplicate of bug 30210 ***

Resolution: (none) => DUPLICATE
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.