[ubuntu/maverick-security] tiff 3.9.4-2ubuntu0.5 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Wed Apr 4 21:03:39 UTC 2012


tiff (3.9.4-2ubuntu0.5) maverick-security; urgency=low

  * SECURITY UPDATE: denial of service and possible code execution via
    tiffdump
    - debian/patches/CVE-2010-4665.patch: prevent integer overflow in
      tools/tiffdump.c.
    - CVE-2010-4665
  * SECURITY UPDATE: arbitrary code execution via size overflow
    - debian/patches/CVE-2012-1173.patch: use TIFFSafeMultiply in
      libtiff/tif_getimage.c, fix TIFFSafeMultiply in libtiff/tiffiop.h.
    - CVE-2012-1173

Date: Mon, 02 Apr 2012 11:01:42 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/maverick/+source/tiff/3.9.4-2ubuntu0.5
-------------- next part --------------
Format: 1.8
Date: Mon, 02 Apr 2012 11:01:42 -0400
Source: tiff
Binary: libtiff4 libtiffxx0c2 libtiff4-dev libtiff-tools libtiff-opengl libtiff-doc
Architecture: source
Version: 3.9.4-2ubuntu0.5
Distribution: maverick-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 libtiff-doc - TIFF manipulation and conversion documentation
 libtiff-opengl - TIFF manipulation and conversion tools
 libtiff-tools - TIFF manipulation and conversion tools
 libtiff4   - Tag Image File Format (TIFF) library
 libtiff4-dev - Tag Image File Format library (TIFF), development files
 libtiffxx0c2 - Tag Image File Format (TIFF) library -- C++ interface
Changes: 
 tiff (3.9.4-2ubuntu0.5) maverick-security; urgency=low
 .
   * SECURITY UPDATE: denial of service and possible code execution via
     tiffdump
     - debian/patches/CVE-2010-4665.patch: prevent integer overflow in
       tools/tiffdump.c.
     - CVE-2010-4665
   * SECURITY UPDATE: arbitrary code execution via size overflow
     - debian/patches/CVE-2012-1173.patch: use TIFFSafeMultiply in
       libtiff/tif_getimage.c, fix TIFFSafeMultiply in libtiff/tiffiop.h.
     - CVE-2012-1173
Checksums-Sha1: 
 469f502b5e7f54a9b3f4cfd4bc5e54b1cfec66bf 1953 tiff_3.9.4-2ubuntu0.5.dsc
 bf953b4809b899f5e6ac31f7fc8d9d7381bd11b2 20765 tiff_3.9.4-2ubuntu0.5.debian.tar.gz
Checksums-Sha256: 
 b8886bf03a5509274bf1bedb6eef20e0ee0c24ed7c06cb658d69bbc4b0c8361b 1953 tiff_3.9.4-2ubuntu0.5.dsc
 3a504ccc8e3ca98fa11b72fec1277a7581bf9f5dec75e0feee32169258b14885 20765 tiff_3.9.4-2ubuntu0.5.debian.tar.gz
Files: 
 3afb008f1a9cdfd2524d32f6cc25f721 1953 libs optional tiff_3.9.4-2ubuntu0.5.dsc
 7b12e38c20c7e7130aed6ca3a8c44edc 20765 libs optional tiff_3.9.4-2ubuntu0.5.debian.tar.gz
Original-Maintainer: Jay Berkenbilt <qjb at debian.org>


More information about the Maverick-changes mailing list