[ubuntu/disco-security] tiff 4.0.10-4ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Thu Oct 17 12:01:59 UTC 2019


tiff (4.0.10-4ubuntu0.1) disco-security; urgency=medium

  * SECURITY UPDATE: incorrect integer overflow checks
    - debian/patches/CVE-2019-14973.patch: fix implementation-defined
      behaviour in libtiff/tif_aux.c, libtiff/tif_getimage.c,
      libtiff/tif_luv.c, libtiff/tif_pixarlog.c, libtiff/tif_read.c,
      libtiff/tif_strip.c, libtiff/tif_tile.c, libtiff/tiffiop.h.
    - debian/libtiff5.symbols: added new symbols.
    - CVE-2019-14973
  * SECURITY UPDATE: heap-based buffer overflow via crafted RGBA image
    - debian/patches/CVE-2019-17546.patch: fix integer overflow in
      libtiff/tif_getimage.c.
    - CVE-2019-17546

Date: 2019-10-16 15:17:26.400524+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/tiff/4.0.10-4ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Disco-changes mailing list