Library of functions for manipulating TIFF format image files
Go to file
RHEL Packaging Agent 321421fc81 Fix CVE-2025-9900: buffer underflow in TIFFReadRGBAImageOriented()
Backported upstream patch to fix buffer underflow crash in
TIFFReadRGBAImageOriented() when handling images with fewer raster
rows than requested. The patch adds verification logic to check
raster dimensions against image dimensions and adjusts accordingly.

Manual conflict resolution was required for libtiff 4.0.9
compatibility, replacing TIFFWarningExtR() with TIFFWarningExt()
to match the function signature available in this version.

CVE: CVE-2025-9900
Upstream fix: d1c0719e00.patch
Resolves: RHEL-112533

This commit was backported by Jotnar, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Jotnar
2025-10-14 14:18:20 +00:00
tests Add tests folder for standard beakerlib 2023-09-21 14:04:18 +02:00
.gitignore Import rpm: c8s 2023-02-27 14:12:19 -05:00
0001-Back-off-the-minimum-required-automake-version-to-1..patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0002-Fix-Makefile.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0003-CVE-2018-5784-Fix-for-bug-2772.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0004-CVE-2018-7456-Fix-NULL-pointer-dereference-in-TIFFPr.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0005-CVE-2017-9935-tiff2pdf-Fix-CVE-2017-9935.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0006-CVE-2017-9935-tiff2pdf-Fix-apparent-incorrect-type-f.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0007-CVE-2017-18013-libtiff-tif_print.c-TIFFPrintDirector.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0008-CVE-2018-8905-LZWDecodeCompat-fix-potential-index-ou.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0009-CVE-2018-10963-TIFFWriteDirectorySec-avoid-assertion.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0010-CVE-2018-17100-avoid-potential-int32-overflows-in-mu.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0011-CVE-2018-18557-JBIG-fix-potential-out-of-bounds-writ.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0012-CVE-2018-18661-tiff2bw-avoid-null-pointer-dereferenc.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0013-bz1602597-Fix-two-resource-leaks.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0014-CVE-2018-12900-check-that-Tile-Width-Samples-Pixel-d.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0015-CVE-2019-14973-Fix-integer-overflow-in-_TIFFCheckMal.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0016-CVE-2019-17546-RGBA-interface-fix-integer-overflow-p.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0017-CVE-2020-35521-CVE-2020-35522-enforce-configurable-m.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0018-CVE-2020-35523-gtTileContig-check-Tile-width-for-ove.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0019-CVE-2020-35524-tiff2pdf.c-properly-calculate-datasiz.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0020-CVE-2020-19131-tiffcrop.c-fix-invertImage-for-bps-2-.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0021-CVE-2022-0561-TIFFFetchStripThing-avoid-calling-memc.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0022-CVE-2022-0562-TIFFReadDirectory-avoid-calling-memcpy.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0023-CVE-2022-22844-tiffset-fix-global-buffer-overflow-fo.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0024-CVE-2022-0865-tif_jbig.c-fix-crash-when-reading-a-fi.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0025-CVE-2022-0891-tiffcrop-fix-issue-380-and-382-heap-bu.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0026-CVE-2022-0924-fix-heap-buffer-overflow-in-tiffcp-278.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0027-CVE-2022-0909-fix-the-FPE-in-tiffcrop-393.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0028-CVE-2022-0908-TIFFFetchNormalTag-avoid-calling-memcp.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0029-CVE-2022-1355-tiffcp-avoid-buffer-overflow-in-mode-s.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0030-move-_TIFFClampDoubleToFloat-to-tif_aux.c.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0031-CVE-2022-2056-CVE-2022-2057-CVE-2022-2058-fix-the-FP.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0032-CVE-2022-2867-CVE-2022-2868-tiffcrop.c-Fix-issue-352.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0033-CVE-2022-2519-CVE-2022-2520-CVE-2022-2521-CVE-2022-2.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0034-CVE-2022-2519-CVE-2022-2520-CVE-2022-2521-CVE-2022-2.patch Auto sync2gitlab import of libtiff-4.0.9-26.el8_7.src.rpm 2022-11-11 04:13:37 +00:00
0035-CVE-2022-3597-CVE-2022-3626-CVE-2022-3627-tiffcrop-d.patch Auto sync2gitlab import of libtiff-4.0.9-27.el8.src.rpm 2023-01-27 02:12:15 +00:00
0036-CVE-2022-3970-TIFFReadRGBATileExt-fix-unsigned-integ.patch Auto sync2gitlab import of libtiff-4.0.9-27.el8.src.rpm 2023-01-27 02:12:15 +00:00
0037-CVE-2022-48281-tiffcrop-Correct-simple-copy-paste-er.patch Fix CVE-2022-48281 2023-05-16 14:38:20 +02:00
0038-CVE-2023-0800-CVE-2023-0801-CVE-2023-0802-CVE-2023-0.patch Fix CVE-2023-0800 CVE-2023-0801 CVE-2023-0802 CVE-2023-0803 CVE-2023-0804 2023-09-21 11:08:24 +02:00
0039-CVE-2022-3599-Revised-handling-of-TIFFTAG_INKNAMES-a.patch Fix CVE-2022-3599 CVE-2022-4645 2024-01-09 14:34:59 +01:00
0040-CVE-2018-15209-Merge-branch-avoid_memory_exhaustion_.patch Fix CVE-2023-6228 CVE-2023-52356 CVE-2023-25433 CVE-2018-15209 2024-05-16 16:31:19 +02:00
0041-CVE-2023-25433-Merge-branch-tiffcrop_correctly_updat.patch Fix CVE-2023-6228 CVE-2023-52356 CVE-2023-25433 CVE-2018-15209 2024-05-16 16:31:19 +02:00
0042-CVE-2023-52356-Merge-branch-fix_622-into-master.patch Fix CVE-2023-6228 CVE-2023-52356 CVE-2023-25433 CVE-2018-15209 2024-05-16 16:31:19 +02:00
0043-CVE-2023-6228-Merge-branch-fix_606_tiffcp_check_also.patch Fix CVE-2023-6228 CVE-2023-52356 CVE-2023-25433 CVE-2018-15209 2024-05-16 16:31:19 +02:00
gating.yaml Bring gating.yaml over from Brew dist-git 2023-03-10 10:57:31 -08:00
libtiff-4.0.9-CVE-2017-17095.patch fix CVE-2017-17095: heap-based buffer overflow in pal2rgb (RHEL-87363) 2025-04-22 23:08:05 +02:00
libtiff-4.6.0-CVE-2024-7006.patch fix CVE-2024-7006 a null pointer dereference in tif_dirinfo (RHEL-52927) 2024-08-29 23:49:28 +02:00
libtiff.spec Fix CVE-2025-9900: buffer underflow in TIFFReadRGBAImageOriented() 2025-10-14 14:18:20 +00:00
RHEL-112533.patch Fix CVE-2025-9900: buffer underflow in TIFFReadRGBAImageOriented() 2025-10-14 14:18:20 +00:00
sources Auto sync2gitlab import of libtiff-4.0.9-21.el8.src.rpm 2022-05-26 10:57:59 -04:00