Bug#692345: tiff: CVE-2012-4564 debdiff patch

2012-11-17 Thread Jay Berkenbilt
Jay Berkenbilt wrote: > Adrian La Duca wrote: > >> Attaching debdiff patches for both squeeze and wheezy/experimental >> packages. > > I uploaded a fixed version to unstable and opened an unblock request > after verifying proper functionality. Although the patch applies > cleanly to the version

Bug#692345: tiff: CVE-2012-4564 debdiff patch

2012-11-17 Thread Jay Berkenbilt
Adrian La Duca wrote: > Attaching debdiff patches for both squeeze and wheezy/experimental > packages. I uploaded a fixed version to unstable and opened an unblock request after verifying proper functionality. Although the patch applies cleanly to the version in squeeze, it does not compile bec

Bug#692345: tiff: CVE-2012-4564 debdiff patch

2012-11-16 Thread Jay Berkenbilt
Thanks all. I will definitely get these uploaded this weekend. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#692345: tiff: CVE-2012-4564 debdiff patch

2012-11-16 Thread Adrian La Duca
Attaching debdiff patches for both squeeze and wheezy/experimental packages. diff -Nru tiff-3.9.4/debian/changelog tiff-3.9.4/debian/changelog --- tiff-3.9.4/debian/changelog 2012-10-05 17:35:50.0 -0400 +++ tiff-3.9.4/debian/changelog 2012-11-16 12:42:26.0 -0500 @@ -1,3 +1,10 @@ +t

Bug#692345: tiff: CVE-2012-4564

2012-11-15 Thread Marc Deslauriers
Package: tiff Version: 4.0.2-4 Followup-For: Bug #692345 User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu raring ubuntu-patch *** /tmp/tmpm0_BMg/bug_body In Ubuntu, the attached patch was applied to achieve the following: * SECURITY UPDATE: denial of service and possible code exec

Bug#692345: tiff: CVE-2012-4564

2012-11-14 Thread Jay Berkenbilt
Adrian La Duca wrote: > Created quilt patch from the Red Hat Bugzilla patch (accepted) > submitted by Huzaifa S. Sidhpurwala > Ref: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-4564 Thank you for doing this. I will try to find time to do the upload this weekend. -- To UNSUBSCRIBE, em

Bug#692345: tiff: CVE-2012-4564

2012-11-14 Thread Adrian La Duca
Created quilt patch from the Red Hat Bugzilla patch (accepted) submitted by Huzaifa S. Sidhpurwala Ref: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-4564 --- a/tools/ppm2tiff.c +++ b/tools/ppm2tiff.c @@ -85,6 +85,7 @@ int c; extern int optind; extern char* optarg; + tmsize_t scanlin

Bug#692345: tiff: CVE-2012-4564

2012-11-05 Thread Moritz Muehlenhoff
Package: tiff Severity: grave Tags: security Justification: user security hole Please see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-4564 Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listm