tiff 4.5.0-5ubuntu1.1 source package in Ubuntu

Changelog

tiff (4.5.0-5ubuntu1.1) lunar-security; urgency=medium

  * SECURITY UPDATE: NULL pointer dereference
    - debian/patches/CVE-2023-2731.patch: avoid crash when trying to read again
      from a strip with a missing end-of-information marker in tif_lzw.c.
    - CVE-2023-2731
  * SECURITY UPDATE: NULL pointer dereference
    - d/p/0001-countInkNamesString-fix-UndefinedBehaviorSanitizer-a.patch: Fix
      undefined behavior in tif_dir.c.
    - CVE-2023-2908
  * SECURITY UPDATE: buffer overflow
    - d/p/0003-Consider-error-return-of-writeSelections.patch: Consider error
      return of writeSelections() in tiffcrop.c.
    - CVE-2023-3618
  * SECURITY UPDATE: heap-based buffer overflow
    - d/p/0004-tiffcrop-correctly-update-buffersize-after-rotateIma.patch:
      correctly update buffersize after rotateImage() and enlarge buffsize and
      check integer overflow within rotateImage() in tiffcrop.c.
    - CVE-2023-25433
  * SECURITY UPDATE: Use after free
    - d/p/0005-tiffcrop-Do-not-reuse-input-buffer-for-subsequent-im.patch: Do
      not reuse input buffer for subsequent images in tiffcrop.c.
    - CVE-2023-26965
  * SECURITY UPDATE: buffer overflow
    - d/p/0006-tif_luv-Check-and-correct-for-NaN-data-in-uv_encode.patch: Check
      and correct for NaN data in uv_encode() in tif_luv.c.
    - CVE-2023-26966
  * SECURITY UPDATE: Integer overflow
    - d/p/0007-tiffcp-fix-memory-corruption-overflow-on-hostile-ima.patch: fix
      memory corruption (overflow) in tiffcp.c.
    - CVE-2023-38288
  * SECURITY UPDATE: Integer overflow
    - d/p/0008-raw2tiff-fix-integer-overflow-and-bypass-of-the-chec.patch: fix
      integer overflow and bypass of the check in raw2tiff.c.
    - CVE-2023-38289

 -- Fabian Toepfer <email address hidden>  Mon, 07 Aug 2023 19:51:46 +0200

Upload details

Uploaded by:
Fabian Toepfer
Uploaded to:
Lunar
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
tiff_4.5.0.orig.tar.bz2 2.0 MiB 638f43d7dea33948d5dee7f39572fc0194d9cc3c74195de9dd26a4388a1f880a
tiff_4.5.0-5ubuntu1.1.debian.tar.xz 29.5 KiB 75d459743344611c6b71efa2c019cd67e1ee7eb1cccfa799021d176d5741a5da
tiff_4.5.0-5ubuntu1.1.dsc 2.4 KiB bd8bf35e1dc713ad766c6165a019299fce500e01563be6a7e179484813ccbb5b

View changes file

Binary packages built by this source

libtiff-dev: Tag Image File Format library (TIFF), development files

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 includes the development files, static library, and header files.

libtiff-doc: TIFF manipulation and conversion documentation

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 contains documentation.

libtiff-opengl: TIFF manipulation and conversion tools

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 contains libtiff tools that depend upon opengl. It complements the
 libtiff-tools package, which contains the libtiff tools that don't
 depend upon opengl.

libtiff-opengl-dbgsym: debug symbols for libtiff-opengl
libtiff-tools: TIFF manipulation and conversion tools

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 includes tools for converting TIFF images to and from other formats
 and tools for doing simple manipulations of TIFF images. See also
 libtiff-opengl.

libtiff-tools-dbgsym: debug symbols for libtiff-tools
libtiff5-dev: Tag Image File Format library (TIFF), development files (transitional package)

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 includes the development files, static library, and header files.
 .
 This is a transitional package. It can safely be removed.

libtiff6: Tag Image File Format (TIFF) library

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 includes the shared library.

libtiff6-dbgsym: debug symbols for libtiff6
libtiffxx6: Tag Image File Format (TIFF) library -- C++ interface

 libtiff is a library providing support for the Tag Image File Format
 (TIFF), a widely used format for storing image data. This package
 includes the shared library for the experimental C++ interfaces.

libtiffxx6-dbgsym: debug symbols for libtiffxx6