DSA-3467-1 tiff -- security update

Related Vulnerabilities: CVE-2015-8665   CVE-2015-8683   CVE-2015-8781   CVE-2015-8782   CVE-2015-8783   CVE-2015-8784  

Several vulnerabilities have been found in tiff, a Tag Image File Format library. Multiple out-of-bounds read and write flaws could cause an application using the tiff library to crash. For the oldstable distribution (wheezy), these problems have been fixed in version 4.0.2-6+deb7u5. For the stable distribution (jessie), these problems have been fixed in version 4.0.3-12.3+deb8u1. For the testing distribution (stretch), these problems have been fixed in version 4.0.6-1. For the unstable distribution (sid), these problems have been fixed in version 4.0.6-1. We recommend that you upgrade your tiff packages.

Debian Security Advisory

DSA-3467-1 tiff -- security update

Date Reported:
06 Feb 2016
Affected Packages:
tiff
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 808968, Bug 809021.
In Mitre's CVE dictionary: CVE-2015-8665, CVE-2015-8683, CVE-2015-8781, CVE-2015-8782, CVE-2015-8783, CVE-2015-8784.
More information:

Several vulnerabilities have been found in tiff, a Tag Image File Format library. Multiple out-of-bounds read and write flaws could cause an application using the tiff library to crash.

For the oldstable distribution (wheezy), these problems have been fixed in version 4.0.2-6+deb7u5.

For the stable distribution (jessie), these problems have been fixed in version 4.0.3-12.3+deb8u1.

For the testing distribution (stretch), these problems have been fixed in version 4.0.6-1.

For the unstable distribution (sid), these problems have been fixed in version 4.0.6-1.

We recommend that you upgrade your tiff packages.