Change logs for tiff source package in Bionic

  • tiff (4.0.9-5ubuntu0.2) bionic-security; urgency=medium
    
      * SECURITY UPDATE: heap over-read in TIFFWriteScanline
        - debian/patches/CVE-2018-10779.patch: fix overflow in
          libtiff/tif_write.c.
        - CVE-2018-10779
      * SECURITY UPDATE: heap over-read in cpSeparateBufToContigBuf
        - debian/patches/CVE-2018-12900-1.patch: check for overflow in
          tools/tiffcp.c.
        - debian/patches/CVE-2018-12900-2.patch: use INT_MAX in tools/tiffcp.c.
        - CVE-2018-12900
        - CVE-2019-7663
      * SECURITY UPDATE: NULL pointer dereference in _TIFFmemcmp
        - debian/patches/CVE-2018-17000.patch: add NULL check in
          libtiff/tif_dirwrite.c.
        - CVE-2018-17000
      * SECURITY UPDATE: NULL pointer dereference in TIFFWriteDirectorySec
        - debian/patches/CVE-2018-19210-1.patch: unset transferfunction field
          if necessary in libtiff/tif_dir.c.
        - debian/patches/CVE-2018-19210-2.patch: fix warning in
          libtiff/tif_dir.c.
        - CVE-2018-19210
      * SECURITY UPDATE: memory leak in TIFFFdOpen
        - debian/patches/CVE-2019-6128.patch: properly handle errors in
          tools/pal2rgb.c.
        - CVE-2019-6128
    
     -- Marc Deslauriers <email address hidden>  Mon, 11 Mar 2019 11:59:03 -0400
  • tiff (4.0.9-5ubuntu0.1) bionic-security; urgency=medium
    
      * SECURITY UPDATE: buffer overflow in LZWDecodeCompat
        - debian/patches/CVE-2018-8905.patch: fix logic in libtiff/tif_lzw.c.
        - CVE-2018-8905
      * SECURITY UPDATE: DoS in TIFFWriteDirectorySec()
        - debian/patches/CVE-2018-10963.patch: avoid assertion in
          libtiff/tif_dirwrite.c.
        - CVE-2018-10963
      * SECURITY UPDATE: multiple overflows
        - debian/patches/CVE-2018-1710x.patch: Avoid overflows in
          tools/pal2rgb.c, tools/tiff2bw.c, tools/ppm2tiff.c.
        - CVE-2018-17100
        - CVE-2018-17101
      * SECURITY UPDATE: JBIGDecode out-of-bounds write
        - debian/patches/CVE-2018-18557.patch: fix issue in libtiff/tif_jbig.c,
          libtiff/tif_read.c.
        - CVE-2018-18557
      * SECURITY UPDATE: NULL pointer dereference in LZWDecode
        - debian/patches/CVE-2018-18661.patch: add checks to tools/tiff2bw.c.
        - CVE-2018-18661
    
     -- Marc Deslauriers <email address hidden>  Thu, 17 Jan 2019 09:13:55 -0500
  • tiff (4.0.9-5) unstable; urgency=high
    
      * Fix CVE-2017-11613: avoid memory exhaustion in
        ChopUpSingleUncompressedStrip() (closes: #869823).
      * Fix CVE-2018-7456: NULL pointer dereference in TIFFPrintDirectory()
        (closes: #891288).
      * Fix CVE-2017-17095: heap-based buffer overflow in pal2rgb tool
        (closes: #883320).
      * Don't specify parallel to debhelper.
      * Update Standards-Version to 4.1.4 .
    
     -- Laszlo Boszormenyi (GCS) <email address hidden>  Sun, 15 Apr 2018 18:13:42 +0000
  • tiff (4.0.9-4ubuntu1) bionic; urgency=medium
    
      * SECURITY UPDATE: DoS in TIFFOpen
        - debian/patches/CVE-2017-11613-1.patch: avoid memory exhaustion in
          libtiff/tif_dirread.c.
        - debian/patches/CVE-2017-11613-2.patch: rework fix in
          libtiff/tif_dirread.c.
        - CVE-2017-11613
      * SECURITY UPDATE: TIFFSetupStrips heap overflow in pal2rgb
        - debian/patches/CVE-2017-17095.patch: add workaround to
          tools/pal2rgb.c.
        - CVE-2017-17095
    
     -- Marc Deslauriers <email address hidden>  Thu, 22 Mar 2018 11:18:42 -0400
  • tiff (4.0.9-4) unstable; urgency=high
    
      * Fix CVE-2018-5784: uncontrolled resource consumption in TIFFSetDirectory()
        (closes: #890441).
    
     -- Laszlo Boszormenyi (GCS) <email address hidden>  Wed, 14 Feb 2018 20:07:21 +0000
  • tiff (4.0.9-3) unstable; urgency=high
    
      * Fix CVE-2017-18013: NULL pointer dereference in TIFFPrintDirectory()
        (closes: #885985).
    
     -- Laszlo Boszormenyi (GCS) <email address hidden>  Mon, 01 Jan 2018 16:26:47 +0000
  • tiff (4.0.9-2) unstable; urgency=high
    
      * Fix CVE-2017-9935: heap-based buffer overflow in the t2p_write_pdf()
        function  (closes: #866109).
      * Update debhelper level to 11 .
      * Update Standards-Version to 4.1.2 .
    
     -- Laszlo Boszormenyi (GCS) <email address hidden>  Fri, 15 Dec 2017 17:45:42 +0000
  • tiff (4.0.9-1) unstable; urgency=medium
    
      * New upstream release.
      * Remove previously backported security patches.
      * Update libtiff5 symbols.
      * Make -dev recommend pkg-config (closes: #814417).
      * Update debhelper level to 10:
        - don't need to specify 'with autotools-dev' anymore,
        - remove autotools-dev build dependency,
        - remove dh-autoreconf build dependency.
    
      [ Helmut Grohne <email address hidden> ]
      * Turn libtiff-dev into a real package (closes: #780807).
    
     -- Laszlo Boszormenyi (GCS) <email address hidden>  Sat, 02 Dec 2017 09:24:59 +0000
  • tiff (4.0.8-6) unstable; urgency=high
    
      * Backport security fixes:
        - prevent OOM in gtTileContig() ,
        - prevent OOM in TIFFFetchStripThing() ,
        - CVE-2017-12944, OOM prevention in TIFFReadDirEntryArray()
          (closes: #872607),
        - avoid floating point division by zero in initCIELabConversion() .
    
     -- Laszlo Boszormenyi (GCS) <email address hidden>  Sun, 29 Oct 2017 13:29:44 +0000
  • tiff (4.0.8-5) unstable; urgency=high
    
      * Backport security fixes:
        - CVE-2017-13726, reachable assertion abort in TIFFWriteDirectorySec()
          (closes: #873880),
        - CVE-2017-13727, reachable assertion abort in
          TIFFWriteDirectoryTagSubifd() (closes: #873879).
    
     -- Laszlo Boszormenyi (GCS) <email address hidden>  Thu, 31 Aug 2017 21:09:59 +0000