LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue
| Software | From | Fixed in |
|---|---|---|
| libtiff / libtiff | 4.0.8 | 4.0.8.x |
| opensuse / leap | 42.3 | 42.3.x |
| opensuse / leap | 42.2 | 42.2.x |
| suse / linux_enterprise_software_development_kit | 12-sp2 | 12-sp2.x |
| suse / linux_enterprise_desktop | 12-sp2 | 12-sp2.x |
| suse / linux_enterprise_server | 12-sp2 | 12-sp2.x |
| suse / linux_enterprise_desktop | 12-sp3 | 12-sp3.x |
| suse / linux_enterprise_server | 12-sp3 | 12-sp3.x |
| suse / linux_enterprise_software_development_kit | 12-sp3 | 12-sp3.x |