tiff 3.7.4-1ubuntu3.2 source package in Ubuntu
Changelog
tiff (3.7.4-1ubuntu3.2) dapper-security; urgency=low * SECURITY UPDATE: Arbitrary code execution with crafted TIFF files, found by Tavis Ormandy of the Google Security Team. * Add debian/patches/CVE-2006-3459-3465.patch: - CVE-2006-3459: a stack buffer overflow via TIFFFetchShortPair() in tif_dirread.c - CVE-2006-3460: A heap overflow vulnerability was discovered in the jpeg decoder - CVE-2006-3461: A heap overflow exists in the PixarLog decoder - CVE-2006-3462: The NeXT RLE decoder was also vulnerable to a heap overflow - CVE-2006-3463: An infinite loop was discovered in EstimateStripByteCounts() - CVE-2006-3464: Multiple unchecked arithmetic operations were uncovered, including a number of the range checking operations deisgned to ensure the offsets specified in tiff directories are legitimate. - A number of codepaths were uncovered where assertions did not hold true, resulting in the client application calling abort() - CVE-2006-3465: A flaw was also uncovered in libtiffs custom tag support -- Martin Pitt <email address hidden> Wed, 2 Aug 2006 13:27:14 +0200
Upload details
- Uploaded by:
- Martin Pitt
- Uploaded to:
- Dapper
- Original maintainer:
- Jay Berkenbilt
- Architectures:
- any
- Section:
- libs
- Urgency:
- Low Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
tiff_3.7.4.orig.tar.gz | 1.2 MiB | ede80aa0760275a518143761df1bd21e202dca03873e9fa4e0336ab986b0bd81 |
tiff_3.7.4-1ubuntu3.2.diff.gz | 18.7 KiB | b360e86b18616bd2019fbb27741e31b247e52ebde31b09d33cbcf34ead0c1e89 |
tiff_3.7.4-1ubuntu3.2.dsc | 758 bytes | 04d9ec523ce1b74a5a36460cf24067234e3692ff07c0c3879ac8d1445f49c9d2 |
Binary packages built by this source
- libtiff-opengl: No summary available for libtiff-opengl in ubuntu dapper.
No description available for libtiff-opengl in ubuntu dapper.
- libtiff-tools: No summary available for libtiff-tools in ubuntu dapper.
No description available for libtiff-tools in ubuntu dapper.
- libtiff4: No summary available for libtiff4 in ubuntu dapper.
No description available for libtiff4 in ubuntu dapper.
- libtiff4-dev: No summary available for libtiff4-dev in ubuntu dapper.
No description available for libtiff4-dev in ubuntu dapper.
- libtiffxx0c2: No summary available for libtiffxx0c2 in ubuntu dapper.
No description available for libtiffxx0c2 in ubuntu dapper.