摘要:
libtiff security update
安全等级: Low
公告ID: KylinSec-SA-2025-2815
发布日期: 2025年9月9日
关联CVE: CVE-2025-8534
This provides support for the Tag Image File Format (TIFF), a widely
used format for storing image data. The latest version of the TIFF specification
is available on-line in several different formats.And contains command-line programs
for manipulating TIFF format image files using the libtiff library.
Security Fix(es):
LibTIFF is a library for reading and writing TIFF (label image file format) files that are open source. This library contains some command-line tools for handling TIFF files.
There is a security vulnerability in the 4.6.0 version of LibTIFF, which originates from the dereference of the null pointer of the function PS_Lvl2page in the file tools/tiff2ps.c.(CVE-2025-8534)
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2025-8534 | KY3.5.3 | libtiff | Fixed |
CVE-2025-8534 | KY3.5.2 | libtiff | Fixed |
软件名称 | 架构 | 版本号 |
---|---|---|
libtiff-help | noarch | 4.3.0-41.ky3_5 |
libtiff | x86_64 | 4.3.0-41.ky3_5 |
libtiff-devel | x86_64 | 4.3.0-41.ky3_5 |
libtiff-static | x86_64 | 4.3.0-41.ky3_5 |
libtiff-tools | x86_64 | 4.3.0-41.ky3_5 |
libtiff | aarch64 | 4.3.0-41.ky3_5 |
libtiff-devel | aarch64 | 4.3.0-41.ky3_5 |
libtiff-static | aarch64 | 4.3.0-41.ky3_5 |
libtiff-tools | aarch64 | 4.3.0-41.ky3_5 |
软件名称 | 架构 | 版本号 |
---|---|---|
libtiff-help | noarch | 4.3.0-41.ky3_5 |
libtiff | x86_64 | 4.3.0-41.ky3_5 |
libtiff-devel | x86_64 | 4.3.0-41.ky3_5 |
libtiff-static | x86_64 | 4.3.0-41.ky3_5 |
libtiff-tools | x86_64 | 4.3.0-41.ky3_5 |
libtiff | aarch64 | 4.3.0-41.ky3_5 |
libtiff-devel | aarch64 | 4.3.0-41.ky3_5 |
libtiff-static | aarch64 | 4.3.0-41.ky3_5 |
libtiff-tools | aarch64 | 4.3.0-41.ky3_5 |
方法一:下载安装包进行升级安装
1、通过下载链接下载需要升级的升级包保存,如 xxx.rpm
2、通过rpm命令升级,如 rpm -Uvh xxx.rpm
方法二:通过软件源进行升级安装
1、保持能够连接上互联网
2、通过yum命令升级指定的包,如 yum install 包名