tiff 4.3.0-6ubuntu0.5 source package in Ubuntu

Changelog

tiff (4.3.0-6ubuntu0.5) jammy-security; urgency=medium

  * SECURITY UPDATE: heap-based buffer overflow
    - debian/patches/CVE-2022-48281.patch: correct simple copy paste error in
      tiffcrop.c.
    - CVE-2022-48281
  * SECURITY UPDATE: NULL pointer dereference
    - d/p/0001-countInkNamesString-fix-UndefinedBehaviorSanitizer-a.patch: Fix
      undefined behavior in tif_dir.c.
    - CVE-2023-2908
  * SECURITY UPDATE: NULL pointer dereference
    - d/p/0002-TIFFClose-avoid-NULL-pointer-dereferencing.-fix-515.patch: avoid
      NULL pointer dereferencing in tif_close.c.
    - CVE-2023-3316
  * SECURITY UPDATE: buffer overflow
    - d/p/0003-Consider-error-return-of-writeSelections.patch: Consider error
      return of writeSelections() in tiffcrop.c.
    - CVE-2023-3618
  * SECURITY UPDATE: heap-based buffer overflow
    - d/p/0004-tiffcrop-correctly-update-buffersize-after-rotateIma.patch:
      correctly update buffersize after rotateImage() and enlarge buffsize and
      check integer overflow within rotateImage() in tiffcrop.c.
    - CVE-2023-25433
  * SECURITY UPDATE: Use after free
    - d/p/0005-tiffcrop-Do-not-reuse-input-buffer-for-subsequent-im.patch: Do
      not reuse input buffer for subsequent images in tiffcrop.c.
    - CVE-2023-26965
  * SECURITY UPDATE: buffer overflow
    - d/p/0006-tif_luv-Check-and-correct-for-NaN-data-in-uv_encode.patch: Check
      and correct for NaN data in uv_encode() in tif_luv.c.
    - CVE-2023-26966
  * SECURITY UPDATE: Integer overflow
    - d/p/0007-tiffcp-fix-memory-corruption-overflow-on-hostile-ima.patch: fix
      memory corruption (overflow) in tiffcp.c.
    - CVE-2023-38288
  * SECURITY UPDATE: Integer overflow
    - d/p/0008-raw2tiff-fix-integer-overflow-and-bypass-of-the-chec.patch: fix
      integer overflow and bypass of the check in raw2tiff.c.
    - CVE-2023-38289

 -- Fabian Toepfer <email address hidden>  Mon, 07 Aug 2023 17:56:53 +0200

Upload details

Uploaded by:
Fabian Toepfer
Uploaded to:
Jammy
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
tiff_4.3.0.orig.tar.gz 2.7 MiB 0e46e5acb087ce7d1ac53cf4f56a09b221537fc86dfc5daaad1c2e89e1b37ac8
tiff_4.3.0.orig.tar.gz.asc 488 bytes 6e41d0a4c042d2903f28534eb696a16409ccde9aaa2d02d06b5daaabbfb94aa7
tiff_4.3.0-6ubuntu0.5.debian.tar.xz 40.8 KiB c31791f05d415a42cb875162155eaae59b44a32363d35788d734bc9cce3a9aef
tiff_4.3.0-6ubuntu0.5.dsc 2.5 KiB 04856aa0ec90f24cd1b2f8653be644c02c21b30a64a4245226513b7258bbf377

View changes file

Binary packages built by this source

libtiff-dev: Tag Image File Format library (TIFF), development files

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 includes the development files, static library, and header files.

libtiff-doc: TIFF manipulation and conversion documentation

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 contains documentation.

libtiff-opengl: TIFF manipulation and conversion tools

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 contains libtiff tools that depend upon opengl. It complements the
 libtiff-tools package, which contains the libtiff tools that don't
 depend upon opengl.

libtiff-opengl-dbgsym: debug symbols for libtiff-opengl
libtiff-tools: TIFF manipulation and conversion tools

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 includes tools for converting TIFF images to and from other formats
 and tools for doing simple manipulations of TIFF images. See also
 libtiff-opengl.

libtiff-tools-dbgsym: debug symbols for libtiff-tools
libtiff5: Tag Image File Format (TIFF) library

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 includes the shared library.

libtiff5-dbgsym: debug symbols for libtiff5
libtiff5-dev: Tag Image File Format library (TIFF), development files (transitional package)

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 includes the development files, static library, and header files.
 .
 This is a transitional package. It can safely be removed.

libtiffxx5: Tag Image File Format (TIFF) library -- C++ interface

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 includes the shared library for the experimental C++ interfaces.

libtiffxx5-dbgsym: debug symbols for libtiffxx5