Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
FS#75608 - [libtiff] CVE-2022-34526
Attached to Project:
Arch Linux
Opened by T.J. Townsend (blakkheim) - Monday, 15 August 2022, 00:02 GMT
Last edited by Toolybird (Toolybird) - Wednesday, 24 August 2022, 22:17 GMT
Opened by T.J. Townsend (blakkheim) - Monday, 15 August 2022, 00:02 GMT
Last edited by Toolybird (Toolybird) - Wednesday, 24 August 2022, 22:17 GMT
|
DetailsDescription:
The attached diff pulls in the upstream commit to fix CVE-2022-34526 and makes the PKGBUILD a little less wordy. Additional info: https://gitlab.com/libtiff/libtiff/-/commit/275735d0354e39c0ac1dc3c0db2120d6f31d1990 |
This task depends upon
Closed by Toolybird (Toolybird)
Wednesday, 24 August 2022, 22:17 GMT
Reason for closing: Fixed
Additional comments about closing: libtiff 4.4.0-4
Wednesday, 24 August 2022, 22:17 GMT
Reason for closing: Fixed
Additional comments about closing: libtiff 4.4.0-4
Comment by David Runge (dvzrv) -
Tuesday, 16 August 2022, 13:00 GMT
This is now available as libtiff 4.4.0-4 in testing/ lib32-libtiff 4.4.0-4 in multilib-testing.
Comment by T.J. Townsend (blakkheim) -
Wednesday, 24 August 2022, 19:57 GMT
Fixed version has been in testing for over a week, so this can probably be closed after it's moved.
libtiff.diff