tiff: CVE-2017-10688

Related Vulnerabilities: CVE-2017-10688   CVE-2017-9936   CVE-2017-9403   CVE-2017-9404   CVE-2016-10095   CVE-2017-9147  

Debian Bug report logs - #866611
tiff: CVE-2017-10688

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Fri, 30 Jun 2017 13:57:01 UTC

Severity: important

Tags: security, upstream

Found in version tiff/4.0.8-2

Fixed in versions tiff/4.0.8-3, tiff/4.0.3-12.3+deb8u4, tiff/4.0.8-2+deb9u1

Done: Laszlo Boszormenyi (GCS) <gcs@debian.org>

Bug is archived. No further changes may be made.

Forwarded to http://bugzilla.maptools.org/show_bug.cgi?id=2712

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Laszlo Boszormenyi (GCS) <gcs@debian.org>:
Bug#866611; Package src:tiff. (Fri, 30 Jun 2017 13:57:04 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Laszlo Boszormenyi (GCS) <gcs@debian.org>. (Fri, 30 Jun 2017 13:57:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: tiff: CVE-2017-10688
Date: Fri, 30 Jun 2017 15:53:41 +0200
Source: tiff
Version: 4.0.8-2
Severity: important
Tags: upstream security
Forwarded: http://bugzilla.maptools.org/show_bug.cgi?id=2712

Hi,

the following vulnerability was published for tiff.

CVE-2017-10688[0]:
| In LibTIFF 4.0.8, there is a assertion abort in the
| TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A
| crafted input will lead to a remote denial of service attack.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-10688
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10688
[1] http://bugzilla.maptools.org/show_bug.cgi?id=2712

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



Reply sent to Laszlo Boszormenyi (GCS) <gcs@debian.org>:
You have taken responsibility. (Sat, 01 Jul 2017 19:39:09 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sat, 01 Jul 2017 19:39:09 GMT) (full text, mbox, link).


Message #10 received at 866611-close@bugs.debian.org (full text, mbox, reply):

From: Laszlo Boszormenyi (GCS) <gcs@debian.org>
To: 866611-close@bugs.debian.org
Subject: Bug#866611: fixed in tiff 4.0.8-3
Date: Sat, 01 Jul 2017 19:37:56 +0000
Source: tiff
Source-Version: 4.0.8-3

We believe that the bug you reported is fixed in the latest version of
tiff, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 866611@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <gcs@debian.org> (supplier of updated tiff package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sat, 01 Jul 2017 18:13:15 +0000
Source: tiff
Binary: libtiff5 libtiffxx5 libtiff5-dev libtiff-tools libtiff-opengl libtiff-doc
Architecture: source all amd64
Version: 4.0.8-3
Distribution: unstable
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Description:
 libtiff-doc - TIFF manipulation and conversion documentation
 libtiff-opengl - TIFF manipulation and conversion tools
 libtiff-tools - TIFF manipulation and conversion tools
 libtiff5   - Tag Image File Format (TIFF) library
 libtiff5-dev - Tag Image File Format library (TIFF), development files
 libtiffxx5 - Tag Image File Format (TIFF) library -- C++ interface
Closes: 866113 866611
Changes:
 tiff (4.0.8-3) unstable; urgency=high
 .
   * Backport security fixes:
     - CVE-2017-9936, memory leak in error code path of JBIGDecode()
       (closes: #866113),
     - prevent out of memory in gtTileContig() on corrupted files,
     - CVE-2017-10688, assertion failure in TIFFWriteDirectoryTagCheckedXXXX()
       (closes: #866611).
   * Add required _TIFFReadEncodedStripAndAllocBuffer@LIBTIFF_4.0 symbol to the
     libtiff5 package.
   * Update Standards-Version to 4.0.0 .
Checksums-Sha1:
 1c42321c6b9dcc5c97adc77a05f4246e4019140b 2157 tiff_4.0.8-3.dsc
 8bb4f433a11c62f7fb058bdfcf4fceec2eb0c793 22472 tiff_4.0.8-3.debian.tar.xz
 ab1dc60e0234ae0d19b81ee347d446ec86be0475 395430 libtiff-doc_4.0.8-3_all.deb
 86c77629d254d10cf3eefeb6e5ca95824e783c96 14154 libtiff-opengl-dbgsym_4.0.8-3_amd64.deb
 e5a450884ef3cca477ee2bfd784008c8d60fbaac 99968 libtiff-opengl_4.0.8-3_amd64.deb
 e983653ef994dbe52087dd88d8d6391854bab42f 351778 libtiff-tools-dbgsym_4.0.8-3_amd64.deb
 c478bb50b512e630916cc91d06bb5e2e8c8326cd 280926 libtiff-tools_4.0.8-3_amd64.deb
 55ca16cbb8f6c5dfaa457f6f66d261e785b48412 370948 libtiff5-dbgsym_4.0.8-3_amd64.deb
 28cb6682aa7fa2ef0d35c941d050c2f5e7771200 359462 libtiff5-dev_4.0.8-3_amd64.deb
 c5b9592d855b2ff97ae778f4efe7fd8f1ac9deac 236994 libtiff5_4.0.8-3_amd64.deb
 54e41819add64bc1b3739148853db05d06730d8a 21010 libtiffxx5-dbgsym_4.0.8-3_amd64.deb
 07bc5433408a140ce1a7aa26c7eb9ec51a86f3b7 95272 libtiffxx5_4.0.8-3_amd64.deb
 a9cd973ce39497c8dc70701ae657f271be59bce5 11105 tiff_4.0.8-3_amd64.buildinfo
Checksums-Sha256:
 68d975990583c60955f96f51fc4e5cc13dbf7cdeb0fdd4f6c832a8d648870098 2157 tiff_4.0.8-3.dsc
 8803ef2917ceb80c472e97d85e86f71a20d04cf7de94ebffcc1b3100f51058ce 22472 tiff_4.0.8-3.debian.tar.xz
 a76ffe929c070f5927053892a3877fed496748c55a59ee09e12695d9993f9ed1 395430 libtiff-doc_4.0.8-3_all.deb
 28130dc0fb80341f5b2344975ebc139715c1229f801c7964faf68378b598dc9c 14154 libtiff-opengl-dbgsym_4.0.8-3_amd64.deb
 0da6a8808c45069bab5c746fbc9fdb9beadd5dca9bd366edcf74612fd136cf55 99968 libtiff-opengl_4.0.8-3_amd64.deb
 74de8b869192b3be710b2328356686442708b8870b650378aa5330cfd820f3cb 351778 libtiff-tools-dbgsym_4.0.8-3_amd64.deb
 0c14b23f93828c03d60688754f480ceb84cea11cbe5be00d94a16f8a40f48fe3 280926 libtiff-tools_4.0.8-3_amd64.deb
 96d4de12febf2e7d448b0f9fba08270b9b8fdfe5451edd409090c81eed7b6914 370948 libtiff5-dbgsym_4.0.8-3_amd64.deb
 e23636e4661f4105d8611bb0f2a9832d7d3123831df30da79e17aa2b3f4be9d5 359462 libtiff5-dev_4.0.8-3_amd64.deb
 0b1b8daf67b8289a3e3549ba3ce32182900730f0a3fe8abd8fc8a2943fe3d43d 236994 libtiff5_4.0.8-3_amd64.deb
 fe6940b05b316a70f108cc64ea3a1c1eb9245887b1dfad6c0eb57df171945fd7 21010 libtiffxx5-dbgsym_4.0.8-3_amd64.deb
 cf7b3f15290b6e046b9b641d796a89fa5bfafff73ecafc8f14eb4dbd54040852 95272 libtiffxx5_4.0.8-3_amd64.deb
 90af28beb3b520288993fdb328e6b9dea5eee12bef63985099cc1e1a8f4a465b 11105 tiff_4.0.8-3_amd64.buildinfo
Files:
 ecdf71818553d6ac59c26fc14b0e71ff 2157 libs optional tiff_4.0.8-3.dsc
 de6cbda54c319f8d047842a31fce346c 22472 libs optional tiff_4.0.8-3.debian.tar.xz
 30cf9e15b31c90f90ba9dd1246d75aec 395430 doc optional libtiff-doc_4.0.8-3_all.deb
 181484f9fdd7dadb8dbc8ef873d362dd 14154 debug extra libtiff-opengl-dbgsym_4.0.8-3_amd64.deb
 bbf0776f9567d6cbccd3fdb263c7e6bc 99968 graphics optional libtiff-opengl_4.0.8-3_amd64.deb
 f5a8db6d1aa800577b9259deed449d03 351778 debug extra libtiff-tools-dbgsym_4.0.8-3_amd64.deb
 651f8dc6d73d2c4b224e7c947e7eb09f 280926 graphics optional libtiff-tools_4.0.8-3_amd64.deb
 a3c4c1fc68f39e505bbefed5823bfdf2 370948 debug extra libtiff5-dbgsym_4.0.8-3_amd64.deb
 3cc6bf3812196feaf1e23b9e5271893e 359462 libdevel optional libtiff5-dev_4.0.8-3_amd64.deb
 de98b650b970244da5ed0b9ac8cccd7f 236994 libs optional libtiff5_4.0.8-3_amd64.deb
 8ca5b56079be1d8ab4c1f93f76cf3f91 21010 debug extra libtiffxx5-dbgsym_4.0.8-3_amd64.deb
 7d511b847f3fc1411423fa76c43574d5 95272 libs optional libtiffxx5_4.0.8-3_amd64.deb
 e4697e1fafa6ef509d3d54649959d43a 11105 libs optional tiff_4.0.8-3_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAllX8kkACgkQ3OMQ54ZM
yL8/hg//fS80kZxH7NRVg/b5D5PQu4Ci2byM52C825msNSmEhiQOhfaSxEaN031E
xjEFwmaz8sN5OFrqwXuLblUtDpPANfMscI20cNxA1tWyBlhuDa23d8pWssAW+1h4
lYHEDgIh45g8sic3JvjDmL3w2Yg5prDq6ksbrxEj2etywggetek+xjRymWp9jX4s
gw6hJ1Q/mxVNw21PSNuk7HCeqzqpt/KAzV+nVmJ1VwfoOqknFVagRKWF594yelDI
82JAdhXm0fZ1AoJzjb6njZtJNSoVG8cahlddndO9fYZp+GqTfm0UAXq3E4vc6TFU
p6zLFLzucW5cs/xhvPDPmJPqg0XO08eZJy/vslQ0Hr/eTGml08w+lOYR+XcWLsWJ
3o5TpdVvZTRPC7iMNpMgIpdaHrB2y08oFX0bpNpX7HWwHejCZdjn9I7x7SSobgiC
pLy65e+qkjRA1K2G2vxD5Yk3NePbhBqHq6j0EEryEBj8Uem5eEOpmF9EuQQERieR
d1t6DySKzqK0caVBoxAgZI0NcVW+8h4n4+WKENss5Fps6TeEW1RwX/P8zH/EqU2R
wcDN6e0w9av6VSaGpstc5EPqYm7K0mZ/wqvCRBk8x/sCX6KlbLBL7gmnMX9mNjL0
frN2byEKQQ5Hhmp03z7Gw1lBs0JPbQ2Ydfgdw8V2mEE6nSzH+4M=
=vUeP
-----END PGP SIGNATURE-----




Reply sent to Laszlo Boszormenyi (GCS) <gcs@debian.org>:
You have taken responsibility. (Sat, 15 Jul 2017 20:51:11 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sat, 15 Jul 2017 20:51:11 GMT) (full text, mbox, link).


Message #15 received at 866611-close@bugs.debian.org (full text, mbox, reply):

From: Laszlo Boszormenyi (GCS) <gcs@debian.org>
To: 866611-close@bugs.debian.org
Subject: Bug#866611: fixed in tiff 4.0.3-12.3+deb8u4
Date: Sat, 15 Jul 2017 20:48:11 +0000
Source: tiff
Source-Version: 4.0.3-12.3+deb8u4

We believe that the bug you reported is fixed in the latest version of
tiff, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 866611@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <gcs@debian.org> (supplier of updated tiff package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sun, 02 Jul 2017 08:35:22 +0000
Source: tiff
Binary: libtiff5 libtiffxx5 libtiff5-dev libtiff-tools libtiff-opengl libtiff-doc
Architecture: source all amd64
Version: 4.0.3-12.3+deb8u4
Distribution: jessie-security
Urgency: high
Maintainer: Ondřej Surý <ondrej@debian.org>
Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Description:
 libtiff-doc - TIFF manipulation and conversion documentation
 libtiff-opengl - TIFF manipulation and conversion tools
 libtiff-tools - TIFF manipulation and conversion tools
 libtiff5   - Tag Image File Format (TIFF) library
 libtiff5-dev - Tag Image File Format library (TIFF), development files
 libtiffxx5 - Tag Image File Format (TIFF) library -- C++ interface
Closes: 850316 863185 866113 866611
Changes:
 tiff (4.0.3-12.3+deb8u4) jessie-security; urgency=high
 .
   * Backport fix for the following vulnerabilities:
     - CVE-2017-9403: fix memory leak in non DEFER_STRILE_LOAD mode,
     - CVE-2017-9404: memory leak vulnerability was found in the function
       OJPEGReadHeaderInfoSecTablesQTable(),
     - CVE-2016-10095 and CVE-2017-9147: add _TIFFCheckFieldIsValidForCodec()
       and use it in TIFFReadDirectory() (closes: #850316, #863185),
     - CVE-2017-9936: memory leak in error code path of JBIGDecode()
       (closes: #866113),
     - prevent out of memory in gtTileContig() on corrupted files,
     - CVE-2017-10688, assertion failure in TIFFWriteDirectoryTagCheckedXXXX()
       (closes: #866611).
   * Add required _TIFFCheckFieldIsValidForCodec@LIBTIFF_4.0 and
     _TIFFReadEncodedStripAndAllocBuffer@LIBTIFF_4.0 symbols to the
     libtiff5 package.
Checksums-Sha1:
 464c9062f2e1c187bfc62fbf2c0685501a8000f8 2240 tiff_4.0.3-12.3+deb8u4.dsc
 96cd34b33632ff0e0c902ea556565b9f2a5684cc 59668 tiff_4.0.3-12.3+deb8u4.debian.tar.xz
 f2773fa8656c505d13cd3bb04cbf6060572f370c 370656 libtiff-doc_4.0.3-12.3+deb8u4_all.deb
 ca29c3ba817fe0938857cfb67aec2ce840cfc99b 221088 libtiff5_4.0.3-12.3+deb8u4_amd64.deb
 e55762a11f627a677e7540cdfb21749354cd5bc3 80488 libtiffxx5_4.0.3-12.3+deb8u4_amd64.deb
 cac90abaa7cf91638b9f44f25f2d9fb61fa47076 343602 libtiff5-dev_4.0.3-12.3+deb8u4_amd64.deb
 43e39ceb07173dcdc3a484514c2b9d3f23debafc 274296 libtiff-tools_4.0.3-12.3+deb8u4_amd64.deb
 81b05e7aaf2c6ec362e3fd180efce9228df731da 85398 libtiff-opengl_4.0.3-12.3+deb8u4_amd64.deb
Checksums-Sha256:
 50e944559c1588ac8cdaca8034a3a74e9178d6f026edc5f48e9c4ab77540e82f 2240 tiff_4.0.3-12.3+deb8u4.dsc
 3e637b2784715aa3a4b6e9111d9265682b73997eed0750460afe29662166595f 59668 tiff_4.0.3-12.3+deb8u4.debian.tar.xz
 42c92b854a55df5e6fd394dd9ffef2dfcb62cbfa23c26e4e4d676d8c3683dade 370656 libtiff-doc_4.0.3-12.3+deb8u4_all.deb
 79eb932460fb975af5f0672201ec656eab1d1f2d0a5f25b0d5308de803b84c77 221088 libtiff5_4.0.3-12.3+deb8u4_amd64.deb
 56ccc8d1c899aaec398132747da046acf1d11f89facd4b3ff08d0400d118dbd8 80488 libtiffxx5_4.0.3-12.3+deb8u4_amd64.deb
 37a9da414935963a1ec63ecfa87fb3b473777aaaa946f8f176e8be80e19865c5 343602 libtiff5-dev_4.0.3-12.3+deb8u4_amd64.deb
 675be25b329c38aec7fd30a96fe73afe4c3b342da4d3d085c118221d1930002c 274296 libtiff-tools_4.0.3-12.3+deb8u4_amd64.deb
 7c6195738305c664d3c9cf63b1b3d5ebba4f8967abc1003e60b6ce4fe8418dfc 85398 libtiff-opengl_4.0.3-12.3+deb8u4_amd64.deb
Files:
 727a6acc201fc2abc6b5ac5764da0c82 2240 libs optional tiff_4.0.3-12.3+deb8u4.dsc
 9020cf788fbae80ed0343543a7d8842d 59668 libs optional tiff_4.0.3-12.3+deb8u4.debian.tar.xz
 c41c8eb083888f7e83d2295d7779acd5 370656 doc optional libtiff-doc_4.0.3-12.3+deb8u4_all.deb
 35a5b92c15fa9e3cf7963d65f740b07f 221088 libs optional libtiff5_4.0.3-12.3+deb8u4_amd64.deb
 4e5b64d38e719871710f9060c1f9ab5a 80488 libs optional libtiffxx5_4.0.3-12.3+deb8u4_amd64.deb
 bfe2ffdf111cdab5b378320c2a3f2b11 343602 libdevel optional libtiff5-dev_4.0.3-12.3+deb8u4_amd64.deb
 25a95583e54acc36e172edf6c62d09ec 274296 graphics optional libtiff-tools_4.0.3-12.3+deb8u4_amd64.deb
 8f825062eb394370e93a613d1b7bce46 85398 graphics optional libtiff-opengl_4.0.3-12.3+deb8u4_amd64.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAllZE24ACgkQ3OMQ54ZM
yL+XuQ//fzg7slqtwL3wAmQpm4G0Q0Jy2iXHxvVmRN70GrsKdK9R4C+EKDf/Eqoi
G5BmKZllwcAX7ao5x4oo9IT5F9zbiRRRV5ZegkK8aUXvoFy22HLh4J1U8c08V7JN
NEttXvoHiNQLrzinwaavi2qRTYJWp7Ga7Ph4DG6PX/G1w8pDjcq0R1TIZZtkiQvY
XYeJ7mE/fapP6N7LlxfFBI6uE4lWa2Lq0e+3ACsFQ6ICylJCRAg1YLVAal1VJOdF
p2sHMtL5SdCAjtqRWGcuOC7NxIRVKpJid62fHWmWeoRLCvtuAT59v/2h5PHyzxwv
mZLeIeA+OjVzfSFzXsKyCaF5tTlsKyjjVs/SN5OmJZVXa2mb6pPZ1cXKl/d0oz4G
FtACpzp201SrW690E9wmUPacbbHc0JiFUv3UJqTFba4/hJ/Bf7tOAp3rBAwv1X01
HIUTecHa5unIVHCC4q2b6w7oL4rfOjIqTwwjZo1SC+R6DhkdWut1i2oWh7BSLFet
J3VoDq4SUhvesvz/jGfjHjR9nnNqYwLCnei74/CTqHkVitoM+hFj1YKYBOPIB5AM
Tg/C63z4k2CQ24Fvsnd10XRI/r9c9daoYNdxq3ap3EH2beHqbQhxXRBdM4QtPEQQ
KHR83iW82O+cyDa6amITuoXcMdo1UQ+p0ZF1RxkrqWLXBMa6BXw=
=2mHB
-----END PGP SIGNATURE-----




Reply sent to Laszlo Boszormenyi (GCS) <gcs@debian.org>:
You have taken responsibility. (Sat, 15 Jul 2017 21:51:32 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sat, 15 Jul 2017 21:51:32 GMT) (full text, mbox, link).


Message #20 received at 866611-close@bugs.debian.org (full text, mbox, reply):

From: Laszlo Boszormenyi (GCS) <gcs@debian.org>
To: 866611-close@bugs.debian.org
Subject: Bug#866611: fixed in tiff 4.0.8-2+deb9u1
Date: Sat, 15 Jul 2017 21:48:32 +0000
Source: tiff
Source-Version: 4.0.8-2+deb9u1

We believe that the bug you reported is fixed in the latest version of
tiff, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 866611@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <gcs@debian.org> (supplier of updated tiff package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sun, 02 Jul 2017 08:36:06 +0000
Source: tiff
Binary: libtiff5 libtiffxx5 libtiff5-dev libtiff-tools libtiff-opengl libtiff-doc
Architecture: source all amd64
Version: 4.0.8-2+deb9u1
Distribution: stretch-security
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Description:
 libtiff-doc - TIFF manipulation and conversion documentation
 libtiff-opengl - TIFF manipulation and conversion tools
 libtiff-tools - TIFF manipulation and conversion tools
 libtiff5   - Tag Image File Format (TIFF) library
 libtiff5-dev - Tag Image File Format library (TIFF), development files
 libtiffxx5 - Tag Image File Format (TIFF) library -- C++ interface
Closes: 866113 866611
Changes:
 tiff (4.0.8-2+deb9u1) stretch-security; urgency=high
 .
   * Backport security fixes:
     - CVE-2017-9936, memory leak in error code path of JBIGDecode()
       (closes: #866113),
     - prevent out of memory in gtTileContig() on corrupted files,
     - CVE-2017-10688, assertion failure in TIFFWriteDirectoryTagCheckedXXXX()
       (closes: #866611).
   * Add required _TIFFReadEncodedStripAndAllocBuffer@LIBTIFF_4.0 symbol to the
     libtiff5 package.
Checksums-Sha1:
 971fd23c33eea7281506675641d6b4daef830473 2185 tiff_4.0.8-2+deb9u1.dsc
 88717c97480a7976c94d23b6d9ed4ac74715267f 2065574 tiff_4.0.8.orig.tar.gz
 901db4f50e21fd2ac682d33e8a9f3a62011992de 22508 tiff_4.0.8-2+deb9u1.debian.tar.xz
 f5f287e70ddde7045a49c64b3a71556b22c914eb 395402 libtiff-doc_4.0.8-2+deb9u1_all.deb
 64164e370688266134be5c1cfc5b62cd25c7e823 14186 libtiff-opengl-dbgsym_4.0.8-2+deb9u1_amd64.deb
 a3519119cd713bfcabd2febf3e48a6a9e1720e37 99980 libtiff-opengl_4.0.8-2+deb9u1_amd64.deb
 84e463d01daced6991bc31002b8bc83d69a25af2 351774 libtiff-tools-dbgsym_4.0.8-2+deb9u1_amd64.deb
 5eab3d801adb687e7a8bfdd6b53d451aee89567e 280796 libtiff-tools_4.0.8-2+deb9u1_amd64.deb
 efb42add726dcdb6fe802fbbc0eceacf512af21d 371102 libtiff5-dbgsym_4.0.8-2+deb9u1_amd64.deb
 2f0c7c6042251032ea40c563fa0d48b39e4e983e 359410 libtiff5-dev_4.0.8-2+deb9u1_amd64.deb
 34b1213e796c8abe017c5ac665edf21dd5586dbe 237022 libtiff5_4.0.8-2+deb9u1_amd64.deb
 c517d4ce68bad9866ed086cd1e04155bbbc9c552 21040 libtiffxx5-dbgsym_4.0.8-2+deb9u1_amd64.deb
 4081bf4460bb3e36ea64e40e831b6b6cc37b7410 95286 libtiffxx5_4.0.8-2+deb9u1_amd64.deb
 da00fbb6859c7e19c53b561a8a9c104feccb3ab4 10842 tiff_4.0.8-2+deb9u1_amd64.buildinfo
Checksums-Sha256:
 81fc0a21746ffbfdf3db69f671e4b4fda5416aedc057f97aec73d6c2889ca10d 2185 tiff_4.0.8-2+deb9u1.dsc
 59d7a5a8ccd92059913f246877db95a2918e6c04fb9d43fd74e5c3390dac2910 2065574 tiff_4.0.8.orig.tar.gz
 a0ed755351bbc4e8a05413316d782c071bccfb1b915767cc9bc09d56f31d34b5 22508 tiff_4.0.8-2+deb9u1.debian.tar.xz
 00a8d890ad5a2fc098594b7f8c95b22664277c7a54534bb6e71aa847fa569e4b 395402 libtiff-doc_4.0.8-2+deb9u1_all.deb
 fd093e5bdba3eb29089320effdf186650e00d78e6c9c76addd5ff516c642da6d 14186 libtiff-opengl-dbgsym_4.0.8-2+deb9u1_amd64.deb
 2dac051b72af51fecad6c6adfd0faf8ebe5ee730893ff2287de77e14295c2302 99980 libtiff-opengl_4.0.8-2+deb9u1_amd64.deb
 56f2f72520e4fc64d13ec6aad6a0677979e7a54897bc5febe970dab50214ebed 351774 libtiff-tools-dbgsym_4.0.8-2+deb9u1_amd64.deb
 aa0ae0553e0e741da257783ce53b2490c2a16036d5cdeff1693e97b372f2515a 280796 libtiff-tools_4.0.8-2+deb9u1_amd64.deb
 af7b76c95269b4014f9a2e54e8e4d71ef33e33d36f8d4a61263325d0ea56a8b8 371102 libtiff5-dbgsym_4.0.8-2+deb9u1_amd64.deb
 79dee27ca371a92e1c10d9c1b5470ee5388f996813c8cf4f727a71b62c19d171 359410 libtiff5-dev_4.0.8-2+deb9u1_amd64.deb
 1457671e46cfab7548ff0f7c4c3bfc9c8484bc8780fd7630b37f076b93500210 237022 libtiff5_4.0.8-2+deb9u1_amd64.deb
 70feeb2a4dd86daececa0f690d77edb585a470ae2ce5243f801d80b1ad03ccc9 21040 libtiffxx5-dbgsym_4.0.8-2+deb9u1_amd64.deb
 4b0b1317365a3b6c86d32149ec42fc3671003c220827d69e0f266ea78da66902 95286 libtiffxx5_4.0.8-2+deb9u1_amd64.deb
 784e20c0ed6234344706c078f6032fb4147f54173d81636d13e2a20f5ffaed5c 10842 tiff_4.0.8-2+deb9u1_amd64.buildinfo
Files:
 a23e9fc57ea25878e9e1987e2b0ebfe3 2185 libs optional tiff_4.0.8-2+deb9u1.dsc
 2a7d1c1318416ddf36d5f6fa4600069b 2065574 libs optional tiff_4.0.8.orig.tar.gz
 ee0cd9531a5a35daa3edbdb479b48d0c 22508 libs optional tiff_4.0.8-2+deb9u1.debian.tar.xz
 bcad7c406cd2660a8e80740b281594df 395402 doc optional libtiff-doc_4.0.8-2+deb9u1_all.deb
 ad566e7ba0640c84021be1fe031c9964 14186 debug extra libtiff-opengl-dbgsym_4.0.8-2+deb9u1_amd64.deb
 9ab77d60d9249a876f495214383141aa 99980 graphics optional libtiff-opengl_4.0.8-2+deb9u1_amd64.deb
 d5078358ffca63630c64a2318c9608df 351774 debug extra libtiff-tools-dbgsym_4.0.8-2+deb9u1_amd64.deb
 7c81a1c2e7145abd2d88ecbce22c3c2b 280796 graphics optional libtiff-tools_4.0.8-2+deb9u1_amd64.deb
 664e31bf4ddff2cd25d91143a0096d19 371102 debug extra libtiff5-dbgsym_4.0.8-2+deb9u1_amd64.deb
 1c1b1860fd8a0db6bb8cffe29f7a86d9 359410 libdevel optional libtiff5-dev_4.0.8-2+deb9u1_amd64.deb
 dbd7cbab9ea6c5c44fad0da25decba97 237022 libs optional libtiff5_4.0.8-2+deb9u1_amd64.deb
 93e1f40d217d117f74134369ae8f8c82 21040 debug extra libtiffxx5-dbgsym_4.0.8-2+deb9u1_amd64.deb
 7ada7176b11bd5513c2d5848ffb117eb 95286 libs optional libtiffxx5_4.0.8-2+deb9u1_amd64.deb
 c340844a1b674c79e1a4acf8af80c101 10842 libs optional tiff_4.0.8-2+deb9u1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAllZE3wACgkQ3OMQ54ZM
yL9njQ/+IyzvLyCmWh4XRhVte1MkyaoqBoccdkhCnhXSl5EB7OTp3Xg17tV941I+
bqCkrhvJr0Lb21RiYc6MJSzV9MEcLuV9Cc+YJChy32ET6Q+SC5T3g2T/Dmipp+Eq
p4DLC5jPhWZhod5Ij/7c3u+7d6dHzUCbhYFO2Uzax8bS1LKTAOv2mIESDOQZnHML
ccZe/UsLH4Ejhg2f90RPZhQvEGYG1FxA7Kx2CmDh43+mlTtHrQ5k1owVvGnpOjZG
r9+I6R+L80xDb07E8HZyexdMlt04cMjLKA4sEj7W2AUK8BFinGsx45UZYl3xftqP
o3dudLVYS6LrrCmtvo2ZzakXlQwyZQzs2uDqAwAUmm4crq619vGwQwk8rNTQEHoi
K2oPNmZWHfBHHs1KOT4q0b4CMqQTGcN5IJLHrQKsFGPXU3FWtMhmdf1yBNHSlPcz
ODRVoPior3y3LyarFDoVlNWqiTDztyFD8ZtIkTHLTWKF5a4D2zdzGZNR6xbQzuCG
sbj+hwj1Nq3s0U/aU4MoIE/jJQG02IoTAg1CHG12lz/xH4FK85sMNfbALxZwowlN
74cogB5EP0vBbPmZoPkqZb+sr3iTYh8ouRQe/y5Dsu/+YVzeNYaxLilXY0toUzx2
E1/PueX/S0xUKQAneLE4QuamIUNIGSB6oSdCKi1x4Oj5b+p+YTk=
=lUV0
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Tue, 15 Aug 2017 07:25:41 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 13:19:37 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.