ALAS2023-2023-351


Amazon Linux 2023 Security Advisory: ALAS-2023-351
Advisory Release Date: 2023-09-14 00:55 Pacific
Advisory Updated Date: 2023-09-20 21:35 Pacific
Severity: Medium

Issue Overview:

An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via crafted TIFF file. (CVE-2022-40090)


Affected Packages:

libtiff


Issue Correction:
Run dnf update libtiff --releasever 2023.2.20230920 to update your system.

New Packages:
aarch64:
    libtiff-static-4.4.0-4.amzn2023.0.14.aarch64
    libtiff-debugsource-4.4.0-4.amzn2023.0.14.aarch64
    libtiff-debuginfo-4.4.0-4.amzn2023.0.14.aarch64
    libtiff-tools-4.4.0-4.amzn2023.0.14.aarch64
    libtiff-devel-4.4.0-4.amzn2023.0.14.aarch64
    libtiff-4.4.0-4.amzn2023.0.14.aarch64
    libtiff-tools-debuginfo-4.4.0-4.amzn2023.0.14.aarch64

src:
    libtiff-4.4.0-4.amzn2023.0.14.src

x86_64:
    libtiff-static-4.4.0-4.amzn2023.0.14.x86_64
    libtiff-debuginfo-4.4.0-4.amzn2023.0.14.x86_64
    libtiff-tools-4.4.0-4.amzn2023.0.14.x86_64
    libtiff-tools-debuginfo-4.4.0-4.amzn2023.0.14.x86_64
    libtiff-devel-4.4.0-4.amzn2023.0.14.x86_64
    libtiff-4.4.0-4.amzn2023.0.14.x86_64
    libtiff-debugsource-4.4.0-4.amzn2023.0.14.x86_64