ALAS2-2023-2158

Related Vulnerabilities: CVE-2023-3576  

Memory leak in memory leak in tiffcrop.c. (CVE-2023-3576)

ALAS2-2023-2158


Amazon Linux 2 Security Advisory: ALAS-2023-2158
Advisory Release Date: 2023-07-20 17:28 Pacific
Advisory Updated Date: 2023-07-25 23:07 Pacific
Severity: Medium

Issue Overview:

Memory leak in memory leak in tiffcrop.c. (CVE-2023-3576)


Affected Packages:

libtiff


Issue Correction:
Run yum update libtiff to update your system.

New Packages:
aarch64:
    libtiff-4.0.3-35.amzn2.0.8.aarch64
    libtiff-devel-4.0.3-35.amzn2.0.8.aarch64
    libtiff-static-4.0.3-35.amzn2.0.8.aarch64
    libtiff-tools-4.0.3-35.amzn2.0.8.aarch64
    libtiff-debuginfo-4.0.3-35.amzn2.0.8.aarch64

i686:
    libtiff-4.0.3-35.amzn2.0.8.i686
    libtiff-devel-4.0.3-35.amzn2.0.8.i686
    libtiff-static-4.0.3-35.amzn2.0.8.i686
    libtiff-tools-4.0.3-35.amzn2.0.8.i686
    libtiff-debuginfo-4.0.3-35.amzn2.0.8.i686

src:
    libtiff-4.0.3-35.amzn2.0.8.src

x86_64:
    libtiff-4.0.3-35.amzn2.0.8.x86_64
    libtiff-devel-4.0.3-35.amzn2.0.8.x86_64
    libtiff-static-4.0.3-35.amzn2.0.8.x86_64
    libtiff-tools-4.0.3-35.amzn2.0.8.x86_64
    libtiff-debuginfo-4.0.3-35.amzn2.0.8.x86_64