<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2025-0237</id>
    <title>An update for libtiff is now available for HCE 2.0</title>
    <severity>Moderate</severity>
    <release>HCE 2.0</release>
    <issued date="2025-09-23 11:51:50"/>
    <updated date="2025-09-23 11:51:50"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-13978" id="CVE-2024-13978" title="CVE-2024-13978 Base Score: 2.5 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-8177" id="CVE-2025-8177" title="CVE-2025-8177 Base Score: 5.3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" type="cve"/>
    </references>
    <description>Security Fix(es):

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the file tools/tiff2pdf.c of the component fax2ps. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation appears to be difficult. The patch is named 2ebfffb0e8836bfb1cd7d85c059cd285c59761a4. It is recommended to apply a patch to fix this issue. (CVE-2024-13978)

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer. (CVE-2025-8177)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="libtiff">
        <name>HCE 2.0</name>
        <package arch="aarch64" name="libtiff" version="4.3.0" release="9.r29.hce2">
          <filename>libtiff-4.3.0-9.r29.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="libtiff-devel" version="4.3.0" release="9.r29.hce2">
          <filename>libtiff-devel-4.3.0-9.r29.hce2.aarch64.rpm</filename>
        </package>
        <package arch="noarch" name="libtiff-help" version="4.3.0" release="9.r29.hce2">
          <filename>libtiff-help-4.3.0-9.r29.hce2.noarch.rpm</filename>
        </package>
        <package arch="aarch64" name="libtiff-static" version="4.3.0" release="9.r29.hce2">
          <filename>libtiff-static-4.3.0-9.r29.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="libtiff-tools" version="4.3.0" release="9.r29.hce2">
          <filename>libtiff-tools-4.3.0-9.r29.hce2.aarch64.rpm</filename>
        </package>
        <package arch="x86_64" name="libtiff" version="4.3.0" release="9.r29.hce2">
          <filename>libtiff-4.3.0-9.r29.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="libtiff-devel" version="4.3.0" release="9.r29.hce2">
          <filename>libtiff-devel-4.3.0-9.r29.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="libtiff-static" version="4.3.0" release="9.r29.hce2">
          <filename>libtiff-static-4.3.0-9.r29.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="libtiff-tools" version="4.3.0" release="9.r29.hce2">
          <filename>libtiff-tools-4.3.0-9.r29.hce2.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
