Source: tiff
Version: 4.0.9-1
Severity: important
Tags: security upstream
Forwarded: http://bugzilla.maptools.org/show_bug.cgi?id=2788
Control: found -1 4.0.3-12.3

Hi,

The following vulnerability was published for tiff, basically filling
as tracking bug until upstream fixes know an affected versions can be
double checked again, but this should go back to 4.0.3-12.3.

CVE-2018-10779[0]:
| TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based
| buffer over-read, as demonstrated by bmp2tiff.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-10779
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10779
[1] http://bugzilla.maptools.org/show_bug.cgi?id=2788

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to