tiff: CVE-2012-4564

Related Vulnerabilities: CVE-2012-4564   CVE-2012-4447   CVE-2012-2113   CVE-2012-3401  

Debian Bug report logs - #692345
tiff: CVE-2012-4564

version graph

Package: tiff; Maintainer for tiff is Laszlo Boszormenyi (GCS) <gcs@debian.org>;

Reported by: Moritz Muehlenhoff <jmm@inutil.org>

Date: Mon, 5 Nov 2012 08:36:01 UTC

Severity: grave

Tags: security

Found in version 4.0.2-4

Fixed in versions tiff/4.0.2-5, tiff/3.9.4-5+squeeze7

Done: Jay Berkenbilt <qjb@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Jay Berkenbilt <qjb@debian.org>:
Bug#692345; Package tiff. (Mon, 05 Nov 2012 08:36:04 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@inutil.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Jay Berkenbilt <qjb@debian.org>. (Mon, 05 Nov 2012 08:36:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@inutil.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: tiff: CVE-2012-4564
Date: Mon, 05 Nov 2012 09:31:03 +0100
Package: tiff
Severity: grave
Tags: security
Justification: user security hole

Please see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-4564

Cheers,
        Moritz



Information forwarded to debian-bugs-dist@lists.debian.org, Jay Berkenbilt <qjb@debian.org>:
Bug#692345; Package tiff. (Wed, 14 Nov 2012 19:54:03 GMT) (full text, mbox, link).


Acknowledgement sent to Adrian La Duca <aladuca@summatus.net>:
Extra info received and forwarded to list. Copy sent to Jay Berkenbilt <qjb@debian.org>. (Wed, 14 Nov 2012 19:54:03 GMT) (full text, mbox, link).


Message #10 received at 692345@bugs.debian.org (full text, mbox, reply):

From: Adrian La Duca <aladuca@summatus.net>
To: 692345@bugs.debian.org
Subject: tiff: CVE-2012-4564
Date: Wed, 14 Nov 2012 14:49:12 -0500
[Message part 1 (text/plain, inline)]
Created quilt patch from the Red Hat Bugzilla patch (accepted) submitted 
by Huzaifa S. Sidhpurwala
Ref: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-4564
[Message part 2 (text/html, inline)]
[CVE-2012-4564.patch (text/x-patch, attachment)]

Information forwarded to debian-bugs-dist@lists.debian.org:
Bug#692345; Package tiff. (Wed, 14 Nov 2012 21:57:10 GMT) (full text, mbox, link).


Acknowledgement sent to Jay Berkenbilt <qjb@debian.org>:
Extra info received and forwarded to list. (Wed, 14 Nov 2012 21:57:10 GMT) (full text, mbox, link).


Message #15 received at 692345@bugs.debian.org (full text, mbox, reply):

From: Jay Berkenbilt <qjb@debian.org>
To: Adrian La Duca <aladuca@summatus.net>
Cc: 692345@bugs.debian.org
Subject: Re: Bug#692345: tiff: CVE-2012-4564
Date: Wed, 14 Nov 2012 16:53:29 -0500
Adrian La Duca <aladuca@summatus.net> wrote:

> Created quilt patch from the Red Hat Bugzilla patch (accepted)
> submitted by Huzaifa S. Sidhpurwala
> Ref: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-4564

Thank you for doing this.  I will try to find time to do the upload this
weekend.



Information forwarded to debian-bugs-dist@lists.debian.org, Jay Berkenbilt <qjb@debian.org>:
Bug#692345; Package tiff. (Thu, 15 Nov 2012 14:21:06 GMT) (full text, mbox, link).


Acknowledgement sent to Marc Deslauriers <marc.deslauriers@ubuntu.com>:
Extra info received and forwarded to list. Copy sent to Jay Berkenbilt <qjb@debian.org>. (Thu, 15 Nov 2012 14:21:06 GMT) (full text, mbox, link).


Message #20 received at 692345@bugs.debian.org (full text, mbox, reply):

From: Marc Deslauriers <marc.deslauriers@ubuntu.com>
To: Debian Bug Tracking System <692345@bugs.debian.org>
Subject: Re: tiff: CVE-2012-4564
Date: Thu, 15 Nov 2012 09:16:27 -0500
[Message part 1 (text/plain, inline)]
Package: tiff
Version: 4.0.2-4
Followup-For: Bug #692345
User: ubuntu-devel@lists.ubuntu.com
Usertags: origin-ubuntu raring ubuntu-patch



*** /tmp/tmpm0_BMg/bug_body

In Ubuntu, the attached patch was applied to achieve the following:

  * SECURITY UPDATE: denial of service and possible code execution via
    crafted PPM image
    - debian/patches/CVE-2012-4564.patch: check scanline_size in
      tools/ppm2tiff.c.
    - CVE-2012-4564


Thanks for considering the patch.


-- System Information:
Debian Release: wheezy/sid
  APT prefers quantal-updates
  APT policy: (500, 'quantal-updates'), (500, 'quantal-security'), (500, 'quantal'), (100, 'quantal-backports')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.5.0-18-generic (SMP w/4 CPU cores)
Locale: LANG=en_CA.UTF-8, LC_CTYPE=en_CA.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
[tiff_4.0.2-4ubuntu2.debdiff (text/x-diff, attachment)]

Information forwarded to debian-bugs-dist@lists.debian.org, Jay Berkenbilt <qjb@debian.org>:
Bug#692345; Package tiff. (Fri, 16 Nov 2012 18:51:06 GMT) (full text, mbox, link).


Acknowledgement sent to Adrian La Duca <aladuca@summatus.net>:
Extra info received and forwarded to list. Copy sent to Jay Berkenbilt <qjb@debian.org>. (Fri, 16 Nov 2012 18:51:06 GMT) (full text, mbox, link).


Message #25 received at 692345@bugs.debian.org (full text, mbox, reply):

From: Adrian La Duca <aladuca@summatus.net>
To: 692345@bugs.debian.org
Subject: tiff: CVE-2012-4564 debdiff patch
Date: Fri, 16 Nov 2012 13:46:32 -0500
[Message part 1 (text/plain, inline)]
Attaching debdiff patches for both squeeze and wheezy/experimental 
packages.
[tiff_3.9.4-5+squeeze7.debdiff (text/plain, attachment)]
[tiff_4.0.2-5.debdiff (text/plain, attachment)]

Information forwarded to debian-bugs-dist@lists.debian.org:
Bug#692345; Package tiff. (Fri, 16 Nov 2012 22:03:03 GMT) (full text, mbox, link).


Acknowledgement sent to Jay Berkenbilt <qjb@debian.org>:
Extra info received and forwarded to list. (Fri, 16 Nov 2012 22:03:03 GMT) (full text, mbox, link).


Message #30 received at 692345@bugs.debian.org (full text, mbox, reply):

From: Jay Berkenbilt <qjb@debian.org>
To: Adrian La Duca <aladuca@summatus.net>, Marc Deslauriers <marc.deslauriers@ubuntu.com>
Cc: 692345@bugs.debian.org
Subject: Re: Bug#692345: tiff: CVE-2012-4564 debdiff patch
Date: Fri, 16 Nov 2012 16:59:15 -0500
Thanks all.  I will definitely get these uploaded this weekend.



Reply sent to Jay Berkenbilt <qjb@debian.org>:
You have taken responsibility. (Sat, 17 Nov 2012 18:51:04 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@inutil.org>:
Bug acknowledged by developer. (Sat, 17 Nov 2012 18:51:04 GMT) (full text, mbox, link).


Message #35 received at 692345-close@bugs.debian.org (full text, mbox, reply):

From: Jay Berkenbilt <qjb@debian.org>
To: 692345-close@bugs.debian.org
Subject: Bug#692345: fixed in tiff 4.0.2-5
Date: Sat, 17 Nov 2012 18:47:52 +0000
Source: tiff
Source-Version: 4.0.2-5

We believe that the bug you reported is fixed in the latest version of
tiff, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 692345@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jay Berkenbilt <qjb@debian.org> (supplier of updated tiff package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sat, 17 Nov 2012 12:40:25 -0500
Source: tiff
Binary: libtiff5 libtiffxx5 libtiff5-dev libtiff5-alt-dev libtiff-tools libtiff-opengl libtiff-doc
Architecture: source all amd64
Version: 4.0.2-5
Distribution: unstable
Urgency: high
Maintainer: Jay Berkenbilt <qjb@debian.org>
Changed-By: Jay Berkenbilt <qjb@debian.org>
Description: 
 libtiff-doc - TIFF manipulation and conversion documentation
 libtiff-opengl - TIFF manipulation and conversion tools
 libtiff-tools - TIFF manipulation and conversion tools
 libtiff5   - Tag Image File Format (TIFF) library
 libtiff5-alt-dev - Tag Image File Format library (TIFF), alternative development fil
 libtiff5-dev - Tag Image File Format library (TIFF), development files
 libtiffxx5 - Tag Image File Format (TIFF) library -- C++ interface
Closes: 692345
Changes: 
 tiff (4.0.2-5) unstable; urgency=high
 .
   * Add fix for CVE-2012-4564, a heap-buffer overflow.  Thanks Adrian La
     Duca for doing all the work to prepare this upload.  (Closes: #692345)
Checksums-Sha1: 
 d1cfd8bcd80521ec3a7f7d41acb12addc036c27c 2124 tiff_4.0.2-5.dsc
 8c30d18a074ec4fa003df36c01e5dc3fca0c16ab 15824 tiff_4.0.2-5.debian.tar.gz
 d722a0a5d7170f1f3e1b2f58b3f01e949f80e7d2 395380 libtiff-doc_4.0.2-5_all.deb
 22263d0c8483fe6d5e1293a559618b4a5fb55aeb 233932 libtiff5_4.0.2-5_amd64.deb
 5406aedcf5b5db039a8d596e7d604f38fed525db 73104 libtiffxx5_4.0.2-5_amd64.deb
 1b3146a53570c9770585acb481d7343dd79c9cb8 375800 libtiff5-dev_4.0.2-5_amd64.deb
 f6f27d7c2b349d3274097d09ba3ec2accb98c84a 295766 libtiff5-alt-dev_4.0.2-5_amd64.deb
 b0133f17ba38137e83fa382ea18ffb829cadbc3d 336864 libtiff-tools_4.0.2-5_amd64.deb
 c7f2d4056dc4fe1bc993dbde881eff33092fab41 78764 libtiff-opengl_4.0.2-5_amd64.deb
Checksums-Sha256: 
 0148e54e6f09fb43192e39c16941d2e589f5582c558a842464042369e2321de0 2124 tiff_4.0.2-5.dsc
 97ee6a100aa98a86ca9e7028bc8a8dd773bf917fd4627aae8682dc49072220e3 15824 tiff_4.0.2-5.debian.tar.gz
 275b8ceed38c08a82f21e27349d21bb74f18be16a776a38fd6541ef4883491b6 395380 libtiff-doc_4.0.2-5_all.deb
 df9b3c2274c76a6de52a6bc62ac6f79687db2b856a4fe52aa097562916fe5f68 233932 libtiff5_4.0.2-5_amd64.deb
 af859b2bbbb1965e56cd02803f31ffcebf79686c523a309e00a1576fd524d436 73104 libtiffxx5_4.0.2-5_amd64.deb
 985e1d7ef6593a822e031b02a21ebb2f6eefe8eaa6d2e46d74bc025684a8a564 375800 libtiff5-dev_4.0.2-5_amd64.deb
 03e8277baa0fd53cd14dd7d638d1d0cacf1b70a45e4b696b06af41cfc1022023 295766 libtiff5-alt-dev_4.0.2-5_amd64.deb
 a6936027365fb3900c71d0b96bdcdab479afb4be931332a92c1509afb1f83bf5 336864 libtiff-tools_4.0.2-5_amd64.deb
 bf015913ccfec078c3e860c39fa7bf8e3490c52ce922461eeb94ccad5cda1761 78764 libtiff-opengl_4.0.2-5_amd64.deb
Files: 
 3176eb248f2794c8a3253bd17add147e 2124 libs optional tiff_4.0.2-5.dsc
 4598d82bb2e8522dca9c1ebc13edcb1a 15824 libs optional tiff_4.0.2-5.debian.tar.gz
 3352277ad38d56c789791d281b592207 395380 doc optional libtiff-doc_4.0.2-5_all.deb
 06bf0b65eb0d7404b0e3b0dfcc0d4281 233932 libs optional libtiff5_4.0.2-5_amd64.deb
 473aa8e6193df44535cf3020bab5d2ac 73104 libs optional libtiffxx5_4.0.2-5_amd64.deb
 6396d6345b92044f44277aacd5e8143a 375800 libdevel optional libtiff5-dev_4.0.2-5_amd64.deb
 d024dde260cac3bc3242672a5f88e512 295766 libdevel optional libtiff5-alt-dev_4.0.2-5_amd64.deb
 709a1582af661f2384b80577661f0d77 336864 graphics optional libtiff-tools_4.0.2-5_amd64.deb
 bdfe5109c77f5aee3045036e4cf864de 78764 graphics optional libtiff-opengl_4.0.2-5_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBAgAGBQJQp9mLAAoJEIp10QmYASx+ajcQAJ7dtA9VoxiGEd27Uk10WQ+L
dV7qGn45Ui8VFHqggVkaB5VzF5EMY/f5w2dZXuBfUwiSxfvIOeX1msNEb74tv5lR
DtE2x/YhfoIyajE1fRbExHzJYDWuum8lNJaECN1UDXyLTBhSpFE0IdbsBST66voQ
+3Bg1b9ecPrZS1SwXry2ZcAT3uSk6DilXbvet9THcGx/rosa1+h87+xMWHEl1JWT
3O3lpZpar16NerLn7sqRlMMr7yulDi5o63czmqvh7fhQaidVWU56MIep+vdCr2aB
5idhpbWH5PwPT9lAXrB8Fbt3DZZAn0EPzpJPP9oF7fxnsZJ+5msYywl2B0xWWXmt
hT23LzWS/yBF7DEtToQ7duw5jV+HZvzfyzRxea4q8nSf2Yr5C1Vnfu5/p/Mz8p6I
NIKSvtMGI/89/i+b/y417dB2M+jPVTTSQBkr8yuZT2kutG3YGj/Nc+TDYEiMRR/O
oDFUZZzYwHorjSVjswiOpuo7EiJ5Xntxwz1mDtiiaXxcsMyBv6hLyTXSJqKGce+Q
k3aLaC1V9Ft7PvgpmYobjioXkX943LNu3q6krB8/nfCDxikynSsR66hI+4xNyomS
IYPGxQqIDMLULBr7Uwe6XfPJP9rf9GqglizTCs+RiV6sRrpd/1PxD4h4FUaFrFen
3sFFN9cyrsT89aAKH+8s
=O9/r
-----END PGP SIGNATURE-----




Information forwarded to debian-bugs-dist@lists.debian.org:
Bug#692345; Package tiff. (Sat, 17 Nov 2012 18:54:03 GMT) (full text, mbox, link).


Acknowledgement sent to Jay Berkenbilt <qjb@debian.org>:
Extra info received and forwarded to list. (Sat, 17 Nov 2012 18:54:03 GMT) (full text, mbox, link).


Message #40 received at 692345@bugs.debian.org (full text, mbox, reply):

From: Jay Berkenbilt <qjb@debian.org>
To: Adrian La Duca <aladuca@summatus.net>
Cc: 692345@bugs.debian.org
Subject: Re: Bug#692345: tiff: CVE-2012-4564 debdiff patch
Date: Sat, 17 Nov 2012 13:50:49 -0500
Adrian La Duca <aladuca@summatus.net> wrote:

> Attaching debdiff patches for both squeeze and wheezy/experimental
> packages.

I uploaded a fixed version to unstable and opened an unblock request
after verifying proper functionality.  Although the patch applies
cleanly to the version in squeeze, it does not compile because tmsize_t
is not defined.  I will look at it later today and create a proper
patch.  The tiff3 packages are not affected because ppm2tiff from that
package is not installed.

Thanks again for doing most of the work here.  I credited you in the
changelog even though it didn't end up being an NMU.  (It's so hard to
keep up with this stuff with two toddlers running around.)

-- 
Jay Berkenbilt <qjb@debian.org>



Information forwarded to debian-bugs-dist@lists.debian.org:
Bug#692345; Package tiff. (Sat, 17 Nov 2012 19:00:03 GMT) (full text, mbox, link).


Acknowledgement sent to Jay Berkenbilt <qjb@debian.org>:
Extra info received and forwarded to list. (Sat, 17 Nov 2012 19:00:03 GMT) (full text, mbox, link).


Message #45 received at 692345@bugs.debian.org (full text, mbox, reply):

From: Jay Berkenbilt <qjb@debian.org>
To: Adrian La Duca <aladuca@summatus.net>
Cc: 692345@bugs.debian.org
Subject: Re: Bug#692345: tiff: CVE-2012-4564 debdiff patch
Date: Sat, 17 Nov 2012 13:57:00 -0500
Jay Berkenbilt <qjb@debian.org> wrote:

> Adrian La Duca <aladuca@summatus.net> wrote:
>
>> Attaching debdiff patches for both squeeze and wheezy/experimental
>> packages.
>
> I uploaded a fixed version to unstable and opened an unblock request
> after verifying proper functionality.  Although the patch applies
> cleanly to the version in squeeze, it does not compile because tmsize_t
> is not defined.  I will look at it later today and create a proper
> patch.  The tiff3 packages are not affected because ppm2tiff from that
> package is not installed.

The fix is trivial...TIFFScanlineSize returns tsize_t instead of
tmsize_t in the older version.  My upload for squeeze is ready.  I'll
just get the security team's okay before uploading.

-- 
Jay Berkenbilt <qjb@debian.org>



Information forwarded to debian-bugs-dist@lists.debian.org:
Bug#692345; Package tiff. (Sat, 17 Nov 2012 19:09:06 GMT) (full text, mbox, link).


Acknowledgement sent to Jay Berkenbilt <qjb@debian.org>:
Extra info received and forwarded to list. (Sat, 17 Nov 2012 19:09:06 GMT) (full text, mbox, link).


Message #50 received at 692345@bugs.debian.org (full text, mbox, reply):

From: Jay Berkenbilt <qjb@debian.org>
To: team@security.debian.org
Cc: 692345@bugs.debian.org
Subject: tiff with CVE-2012-4564 fix ready for stable-security
Date: Sat, 17 Nov 2012 14:05:29 -0500
[Message part 1 (text/plain, inline)]
I have an upload of tiff 3.9.4-5+squeeze7 build against squeeze ready to
upload to stable-security.  This includes a fix for CVE-2012-4564.  I've
attached the debdiff.  Please let me know if I should proceed with the
upload.  Thanks.

-- 
Jay Berkenbilt <qjb@debian.org>

[tiff_3.9.4-5+squeeze6-to-squeeze7.debdiff (text/x-patch, inline)]
diff -Nru tiff-3.9.4/debian/changelog tiff-3.9.4/debian/changelog
--- tiff-3.9.4/debian/changelog	2012-10-05 17:35:50.000000000 -0400
+++ tiff-3.9.4/debian/changelog	2012-11-17 12:44:54.000000000 -0500
@@ -1,3 +1,10 @@
+tiff (3.9.4-5+squeeze7) stable-security; urgency=high
+
+  * Add fix for CVE-2012-4564, a heap-buffer overflow.  Thanks Adrian La
+    Duca for doing all the work to prepare this upload.  (Closes: #692345)
+
+ -- Jay Berkenbilt <qjb@debian.org>  Sat, 17 Nov 2012 12:44:54 -0500
+
 tiff (3.9.4-5+squeeze6) stable-security; urgency=high
 
   * Add fix for CVE-2012-4447, a buffer overrun.  (Closes: #688944)
diff -Nru tiff-3.9.4/debian/patches/CVE-2012-4564.patch tiff-3.9.4/debian/patches/CVE-2012-4564.patch
--- tiff-3.9.4/debian/patches/CVE-2012-4564.patch	1969-12-31 19:00:00.000000000 -0500
+++ tiff-3.9.4/debian/patches/CVE-2012-4564.patch	2012-11-17 13:54:20.000000000 -0500
@@ -0,0 +1,31 @@
+Index: tiff-3.9.4/tools/ppm2tiff.c
+===================================================================
+--- tiff-3.9.4.orig/tools/ppm2tiff.c	2012-11-16 12:43:39.000000000 -0500
++++ tiff-3.9.4/tools/ppm2tiff.c	2012-11-16 12:43:54.000000000 -0500
+@@ -85,6 +85,7 @@
+ 	int c;
+ 	extern int optind;
+ 	extern char* optarg;
++	tsize_t scanline_size;
+ 
+ 	if (argc < 2) {
+ 	    fprintf(stderr, "%s: Too few arguments\n", argv[0]);
+@@ -233,8 +234,16 @@
+ 	}
+ 	if (TIFFScanlineSize(out) > linebytes)
+ 		buf = (unsigned char *)_TIFFmalloc(linebytes);
+-	else
+-		buf = (unsigned char *)_TIFFmalloc(TIFFScanlineSize(out));
++	else {
++		scanline_size = TIFFScanlineSize(out);
++		if (scanline_size != 0)
++			buf = (unsigned char *)_TIFFmalloc(TIFFScanlineSize(out));
++		else {
++			fprintf(stderr, "%s: scanline size overflow\n",infile);
++			(void) TIFFClose(out);
++			exit(-2);
++			}
++		}
+ 	if (resolution > 0) {
+ 		TIFFSetField(out, TIFFTAG_XRESOLUTION, resolution);
+ 		TIFFSetField(out, TIFFTAG_YRESOLUTION, resolution);
diff -Nru tiff-3.9.4/debian/patches/series tiff-3.9.4/debian/patches/series
--- tiff-3.9.4/debian/patches/series	2012-10-05 17:35:50.000000000 -0400
+++ tiff-3.9.4/debian/patches/series	2012-11-17 12:44:06.000000000 -0500
@@ -17,3 +17,4 @@
 CVE-2012-2113.patch
 CVE-2012-3401.patch
 CVE-2012-4447.patch
+CVE-2012-4564.patch

Reply sent to Jay Berkenbilt <qjb@debian.org>:
You have taken responsibility. (Wed, 21 Nov 2012 23:06:03 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@inutil.org>:
Bug acknowledged by developer. (Wed, 21 Nov 2012 23:06:03 GMT) (full text, mbox, link).


Message #55 received at 692345-close@bugs.debian.org (full text, mbox, reply):

From: Jay Berkenbilt <qjb@debian.org>
To: 692345-close@bugs.debian.org
Subject: Bug#692345: fixed in tiff 3.9.4-5+squeeze7
Date: Wed, 21 Nov 2012 23:02:06 +0000
Source: tiff
Source-Version: 3.9.4-5+squeeze7

We believe that the bug you reported is fixed in the latest version of
tiff, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 692345@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jay Berkenbilt <qjb@debian.org> (supplier of updated tiff package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sat, 17 Nov 2012 12:44:54 -0500
Source: tiff
Binary: libtiff4 libtiffxx0c2 libtiff4-dev libtiff-tools libtiff-opengl libtiff-doc
Architecture: source all amd64
Version: 3.9.4-5+squeeze7
Distribution: stable-security
Urgency: high
Maintainer: Jay Berkenbilt <qjb@debian.org>
Changed-By: Jay Berkenbilt <qjb@debian.org>
Description: 
 libtiff-doc - TIFF manipulation and conversion documentation
 libtiff-opengl - TIFF manipulation and conversion tools
 libtiff-tools - TIFF manipulation and conversion tools
 libtiff4   - Tag Image File Format (TIFF) library
 libtiff4-dev - Tag Image File Format library (TIFF), development files
 libtiffxx0c2 - Tag Image File Format (TIFF) library -- C++ interface
Closes: 692345
Changes: 
 tiff (3.9.4-5+squeeze7) stable-security; urgency=high
 .
   * Add fix for CVE-2012-4564, a heap-buffer overflow.  Thanks Adrian La
     Duca for doing all the work to prepare this upload.  (Closes: #692345)
Checksums-Sha1: 
 359f22848bac54beb003ff49f24bdb9de7a8595e 1872 tiff_3.9.4-5+squeeze7.dsc
 552ce11624c6ebe3260b75be434faf50af07bcdf 24094 tiff_3.9.4-5+squeeze7.debian.tar.gz
 4e891f76e0fcc3c446147462532f90cbcba4d51e 386266 libtiff-doc_3.9.4-5+squeeze7_all.deb
 220a5221459cb5efd167cb289f07f0cace0ecb47 195326 libtiff4_3.9.4-5+squeeze7_amd64.deb
 23127933380aaea385bf11e0d5777f0e9e0d389d 59234 libtiffxx0c2_3.9.4-5+squeeze7_amd64.deb
 d49a9812bdbe789ec3e8c665d4b4e178c9dccc9e 322306 libtiff4-dev_3.9.4-5+squeeze7_amd64.deb
 6ab94b4edc037bc58653d26225a334a702c73d1e 302730 libtiff-tools_3.9.4-5+squeeze7_amd64.deb
 55e67de9ece7c131c656e7f454ee1cee4de6b3a7 64658 libtiff-opengl_3.9.4-5+squeeze7_amd64.deb
Checksums-Sha256: 
 ebdbe26df5feaee4ecfe07dea3630aba7752d1bc1e6f8825a4f620dbfe01d4a6 1872 tiff_3.9.4-5+squeeze7.dsc
 7e4b693270e046afec76fdd4e49d7a4dfa485caf636eba1e621b3adcf6ec6e56 24094 tiff_3.9.4-5+squeeze7.debian.tar.gz
 70a39de0a604139234f167e86b5803087f39780d23770c6ecb1cd5e1257318c4 386266 libtiff-doc_3.9.4-5+squeeze7_all.deb
 8d4995d72faca18da850c4b25f32d18ca64b13030498df58b0a80f9985cd6314 195326 libtiff4_3.9.4-5+squeeze7_amd64.deb
 faefe908971366095798e9c4b059c983196c0c873fc4b69e4c1ca1a223b489b3 59234 libtiffxx0c2_3.9.4-5+squeeze7_amd64.deb
 bca27dde50295bb7af6917090c486f3df6471d0999b3e897a6599cd7cbc14b3e 322306 libtiff4-dev_3.9.4-5+squeeze7_amd64.deb
 999cc116905e025e8927387dd9c3477a40e57fa6bf938fb3c974869ec1f309f2 302730 libtiff-tools_3.9.4-5+squeeze7_amd64.deb
 929e623d5b3ae3ed61f8103dca697b7287b075145cecb40a8db119a8a18c816a 64658 libtiff-opengl_3.9.4-5+squeeze7_amd64.deb
Files: 
 6db42e109e915f4fbfeef9c1d0a35b62 1872 libs optional tiff_3.9.4-5+squeeze7.dsc
 0cf9544d7cbd0ffad51ae5cf2467df79 24094 libs optional tiff_3.9.4-5+squeeze7.debian.tar.gz
 5adb7fe50e70430060737d3a2a2dde5d 386266 doc optional libtiff-doc_3.9.4-5+squeeze7_all.deb
 34c4a9870b2c215531d6a59f0c44ce1e 195326 libs optional libtiff4_3.9.4-5+squeeze7_amd64.deb
 dd1057741a645202224e43f8a320f72e 59234 libs optional libtiffxx0c2_3.9.4-5+squeeze7_amd64.deb
 216a2f266111ef0766e81b7457d3060a 322306 libdevel optional libtiff4-dev_3.9.4-5+squeeze7_amd64.deb
 9cc8e3b6364fd81fee249e05dde227cb 302730 graphics optional libtiff-tools_3.9.4-5+squeeze7_amd64.deb
 503f52d161d88957884d415cf6f647f1 64658 graphics optional libtiff-opengl_3.9.4-5+squeeze7_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBAgAGBQJQp95GAAoJEIp10QmYASx+F1gP+QHH8+UMFFh78uUZx/ze7QdC
TP11S9McwMeb8bmHhqSS8FivHvCnZUsAbHWCnWeSOLwdACTkr9F22TahjjAqJIu3
kxoyoY5knGi2AR976XBrp8U9kBc0/NIP6zpr21aBZ3IDHbu5OwVpRQ2a5GYNKuOQ
kAjXRr4imPXB8QsaKGfa4BB24SQIOAYvvg6qGgiPrWbhDMYDcUdgEY8zDzRcmeWD
1/y7NsvRMraOIa8mFHwmQloNyC4gnN06u7m+N/o6KMKR0YMMzS5WpdE9eeUJHhDV
bVu4xkfKCs7A429vHQkT4tMJFVtgizkzFrHDXsn45o3Dxcl+3vbO7lFcSa70OmfW
NqZQqeDE71Cll+jBa/VqRfVjBhfamH2Hrrm8T2oVvhQaNtV5F1KebizW6CpOo35j
lhJmC4B+Qkj5vbGvZddU1fE5/ThE94zl+hoEZXKaVUPDsJe2E6FXiQW407ls7dj/
yXP1Y/VXLFZfcZ1DCXue+ZOSVTcYWoL37IgH3Yk0x9TtrW+iNR+/3d7hzBMEjDMC
USKuKex/9nCtR4ljGCjkt2cDB0idaVEqDfyQJLUtkBHmq+54ipNrcx/vn5EtAK7D
oaWoY1/UFS7B4DGISEs/PLBteby6C79em0E73/R+73ScCtKmHdQGiHFRGfln2THs
2KIHmpueyR+UJkXSgmBV
=vDzH
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Thu, 20 Dec 2012 07:28:04 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 14:26:22 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.