Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
FS#77437 - [libtiff] CVE-2022-48281
Attached to Project:
Arch Linux
Opened by T.J. Townsend (blakkheim) - Wednesday, 08 February 2023, 19:17 GMT
Last edited by Christian Hesse (eworm) - Friday, 17 February 2023, 20:56 GMT
Opened by T.J. Townsend (blakkheim) - Wednesday, 08 February 2023, 19:17 GMT
Last edited by Christian Hesse (eworm) - Friday, 17 February 2023, 20:56 GMT
|
DetailsDescription:
Attached diff adds the upstream libtiff fix for CVE-2022-48281 Additional info: Other patches to consider but didn't seem important enough to me: https://sources.debian.org/src/tiff/4.5.0-4/debian/patches/TIFFSetDirectory_avoid_harmless_unsigned-integer-overflow.patch/ https://sources.debian.org/src/tiff/4.5.0-4/debian/patches/TIFFWriteDirectorySec_avoid_harmless_unsigned-integer-overflow.patch/ |
This task depends upon
Closed by Christian Hesse (eworm)
Friday, 17 February 2023, 20:56 GMT
Reason for closing: Fixed
Additional comments about closing: libtiff 4.5.0-2
Friday, 17 February 2023, 20:56 GMT
Reason for closing: Fixed
Additional comments about closing: libtiff 4.5.0-2
libtiff.diff