Ubuntu has issued an advisory on September 8: https://ubuntu.com/security/notices/USN-5604-1 The issues are fixed upstream in 4.4.0rc1.
Status comment: (none) => Fixed upstream in 4.4.0rc1
Suggested advisory: ======================== The updated packages fix security vulnerabilities: libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further exploitation. (CVE-2022-2867) libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop. (CVE-2022-2868) libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into opening the crafted file with tiffcrop. Triggering this flaw could cause a crash or potentially further exploitation. (CVE-2022-2869) References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2867 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2868 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2869 https://ubuntu.com/security/notices/USN-5604-1 ======================== Updated packages in core/updates_testing: ======================== lib(64)tiff5-4.2.0-1.8.mga8 lib(64)tiff-devel-4.2.0-1.8.mga8 lib(64)tiff-static-devel-4.2.0-1.8.mga8 libtiff-progs-4.2.0-1.8.mga8 from SRPM: libtiff-4.2.0-1.8.mga8.src.rpm
Assignee: nicolas.salguero => qa-bugsStatus comment: Fixed upstream in 4.4.0rc1 => (none)CC: (none) => nicolas.salgueroStatus: NEW => ASSIGNED
MGA8-64 Plasma on Acer Aspire 5253 No installation issues Ref wiki and bug 30228 for testing $ tiffgt zwawi0001-2.tiff displays OK $ tiffdump zwawi0001-2.tiff > tifdump $ more tifdump zwawi0001-2.tiff: Magic: 0x4949 <little-endian> Version: 0x2a <ClassicTIFF> Directory 0: offset 15440520 (0xeb9a88) next 0 (0) SubFileType (254) LONG (4) 1<0> ImageWidth (256) SHORT (3) 1<3398> ImageLength (257) SHORT (3) 1<2272> BitsPerSample (258) SHORT (3) 2<8 8> Compression (259) SHORT (3) 1<1> Photometric (262) SHORT (3) 1<1> DocumentName (269) ASCII (2) 68</home/herman/HV/fotos/zw ...> ImageDescription (270) ASCII (2) 18<Created with GIMP\0> StripOffsets (273) LONG (4) 36<8 434952 869896 1304840 1739784 2174728 2609672 3044616 3479560 3914504 4349448 4784392 5219336 5654280 6089224 6524168 6959112 7394056 7829000 8263944 8698888 9133832 9568776 10003720 ...> Orientation (274) SHORT (3) 1<1> SamplesPerPixel (277) SHORT (3) 1<2> RowsPerStrip (278) SHORT (3) 1<64> StripByteCounts (279) LONG (4) 36<434944 434944 434944 434944 434944 434944 434944 434944 434944 434944 434944 434944 434944 434944 43 4944 434944 434944 434944 434944 434944 434944 434944 434944 434944 ...> XResolution (282) RATIONAL (5) 1<2400> YResolution (283) RATIONAL (5) 1<2400> PlanarConfig (284) SHORT (3) 1<1> ResolutionUnit (296) SHORT (3) 1<2> ExtraSamples (338) SHORT (3) 1<1> $ tiffsplit rietkleur002.tif z TIFFReadDirectory: Warning, Sum of Photometric type-related color channels and ExtraSamples doesn't match SamplesPerPixel. Defining non-color channels as ExtraSamples.. $ ls z* zaaa.tif This is OK as I don't have a multipage tif available $ tiffmedian -C 128 -f rietkleur002.tif median.tif TIFFReadDirectory: Warning, Sum of Photometric type-related color channels and ExtraSamples doesn't match SamplesPerPixel. Defining non-color channels as ExtraSamples.. $ tifftopnm rietkleur002.tif > image.pnm TIFFReadDirectory: Warning, Sum of Photometric type-related color channels and ExtraSamples doesn't match SamplesPerPixel. Defining non-color channels as ExtraSamples.. tifftopnm: writing PPM file $ display image.pnm display is OK $ tiffcrop -E top -U px -m 200,200,200,200 rietkleur001.tif cropped.tif TIFFReadDirectory: Warning, Sum of Photometric type-related color channels and ExtraSamples doesn't match SamplesPerPixel. Defining non-color channels as ExtraSamples.. $ tiff2bw bertanciaux.tif imagebw.tif $ tiff2pdf 1973-024.tif > image.pdf $ tiff2ps 1973-024.tif > image.ps $ gs image.ps GPL Ghostscript 9.53.3 (2020-10-01) Copyright (C) 2020 Artifex Software, Inc. All rights reserved. This software is supplied under the GNU AGPLv3 and comes with NO WARRANTY: see the file COPYING for details. >>showpage, press <return> to continue<< All generated files display OK.
CC: (none) => herman.viaeneWhiteboard: (none) => MGA8-64-OK
Validating. Advisory in Comment 1.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
CC: (none) => davidwhodginsKeywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2022-0337.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED