Back to bug 1395264

Who When What Removed Added
Andrej Nemec 2016-11-15 14:31:34 UTC Depends On 1395166
Andrej Nemec 2016-11-15 14:31:45 UTC Depends On 1395167
Andrej Nemec 2016-11-15 14:31:54 UTC Depends On 1395266
Norman Sardella 2016-11-15 14:48:25 UTC CC sardella
Doran Moppert 2016-11-17 07:05:14 UTC Blocks 1395169
Doran Moppert 2016-11-17 07:10:45 UTC CC amaris
Doran Moppert 2016-11-17 07:12:59 UTC Summary CVE-2016-9297 libtiff: Segmentation fault in _TIFFPrintField (tif_print.c:127) CVE-2016-9297 libtiff: Out-of-bounds heap read in _TIFFPrintField (tif_print.c:127)
Slawomir Czarko 2016-11-17 09:49:38 UTC CC slawomir
Doran Moppert 2016-11-21 04:21:13 UTC Priority medium low
Whiteboard impact=moderate,public=20161107,reported=20161112,source=oss-security,cvss2=4.3/AV:N/AC:M/Au:N/C:N/I:N/A:P,cvss3=3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L,rhel-5/libtiff=wontfix,rhel-6/libtiff=wontfix,rhel-7/libtiff=wontfix,rhel-7/compat-libtiff3=wontfix,fedora-all/libtiff=affected,fedora-all/mingw-libtiff=affected,epel-7/mingw-libtiff=affected impact=low,public=20161107,reported=20161112,source=oss-security,cvss2=4.3/AV:N/AC:M/Au:N/C:N/I:N/A:P,cvss3=3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L,cwe=CWE-170,rhel-5/libtiff=wontfix,rhel-6/libtiff=wontfix,rhel-7/libtiff=wontfix,rhel-7/compat-libtiff3=wontfix,fedora-all/libtiff=affected,fedora-all/mingw-libtiff=affected,epel-7/mingw-libtiff=affected
Severity medium low
Doran Moppert 2016-11-23 07:02:08 UTC Whiteboard impact=low,public=20161107,reported=20161112,source=oss-security,cvss2=4.3/AV:N/AC:M/Au:N/C:N/I:N/A:P,cvss3=3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L,cwe=CWE-170,rhel-5/libtiff=wontfix,rhel-6/libtiff=wontfix,rhel-7/libtiff=wontfix,rhel-7/compat-libtiff3=wontfix,fedora-all/libtiff=affected,fedora-all/mingw-libtiff=affected,epel-7/mingw-libtiff=affected impact=low,public=20161107,reported=20161112,source=oss-security,cvss2=4.3/AV:N/AC:M/Au:N/C:N/I:N/A:P,cvss3=3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L,cwe=CWE-170,rhel-5/libtiff=notaffected,rhel-6/libtiff=wontfix,rhel-7/libtiff=wontfix,rhel-7/compat-libtiff3=wontfix,fedora-all/libtiff=affected,fedora-all/mingw-libtiff=affected,epel-7/mingw-libtiff=affected
Doran Moppert 2016-11-23 07:12:19 UTC Doc Text An out-of-bounds heap read was discovered in libtiff. A crafted file could cause the application to crash or, potentially, disclose process memory.
Doran Moppert 2016-11-23 07:12:47 UTC Status NEW CLOSED
Resolution --- WONTFIX
Last Closed 2016-11-23 02:12:47 UTC
Adam Mariš 2016-11-29 12:39:41 UTC CC amaris
Product Security DevOps Team 2019-09-29 14:00:54 UTC Whiteboard impact=low,public=20161107,reported=20161112,source=oss-security,cvss2=4.3/AV:N/AC:M/Au:N/C:N/I:N/A:P,cvss3=3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L,cwe=CWE-170,rhel-5/libtiff=notaffected,rhel-6/libtiff=wontfix,rhel-7/libtiff=wontfix,rhel-7/compat-libtiff3=wontfix,fedora-all/libtiff=affected,fedora-all/mingw-libtiff=affected,epel-7/mingw-libtiff=affected

Back to bug 1395264