ELA-447-1 tiff security update

DoS or arbitrary code execution

2021-06-28
Packagetiff
Version4.0.3-12.3+deb8u11
Related CVEs CVE-2020-35523 CVE-2020-35524


Two vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service or the execution of arbitrary code if malformed image files are processed.



For Debian 8 jessie, these problems have been fixed in version 4.0.3-12.3+deb8u11.

We recommend that you upgrade your tiff packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.