First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 91584
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Tavis Ormandy (RETIRED) <taviso@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
tiffdiffliffyiff samples vulnerability patch patch Tavis Ormandy (RETIRED) 2005-05-07 08:56 0000 3.33 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 91584 depends on: Show dependency tree
Bug 91584 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-05-05 09:32 0000
libtiff is vulnerable to a buffer overflow when a malformed value is set as
BitsPerSample.

Upstream has been informed:
http://bugzilla.remotesensing.org/show_bug.cgi?id=843

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-05-05 09:54:29 0000 -------
Proposed patch by upstream attached to referenced bug.

Steve please commit an updated ebuild.

------- Comment #2 From Tavis Ormandy (RETIRED) 2005-05-05 11:05:36 0000 -------
upstream developer has stated that this has now been fixed in cvs. (see URL
above)

------- Comment #3 From Tavis Ormandy (RETIRED) 2005-05-07 08:56:08 0000 -------
Created an attachment (id=58276) [edit]
samples vulnerability patch

Here's the patch from cvs, the ChangeLog indicates the 1.52 revision was
incomplete, so these are the updates from 1.51-1.53.

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-05-07 10:39:01 0000 -------
Steve provide an updated ebuild.

------- Comment #5 From Sune Kloppenborg Jeppesen 2005-05-07 10:55:35 0000 -------
Of course should have been Steve please provide an updated ebuild.

------- Comment #6 From Steve Arnold 2005-05-08 11:27:21 0000 -------
Now in CVS:
  +files/tiff-3.7.2-buffer_check.patch, -tiff-3.7.0.ebuild,
  -tiff-3.7.1.ebuild, +tiff-3.7.2.ebuild:
  bump, cleanup, and patch for bug 91584

The new ebuild is all ~arch with the patch; the two older stable ebuilds are not 
patched (haven't tried yet).  3.7.2 is listed on the maptools.org site as both
latest stable and latest development release.

------- Comment #7 From Sune Kloppenborg Jeppesen 2005-05-08 11:42:52 0000 -------
Thx Steve.

Devs please test and mark 3.7.2 stable.

alpha: kloeri
amd64: eradicator
ppc: josejx
sparc: gustavoz
x86: tester

arm hppa ia64 mips ppc64 ppc-macos s390 will be called shortly.

------- Comment #8 From Jeremy Huddleston (RETIRED) 2005-05-08 16:13:11 0000 -------
I'm testing for amd64 and sparc now... is this really neccessary:

pkg_postinst() {
        einfo "Latest tiff with bug #91584 fixes."
}

------- Comment #9 From Gustavo Zacarias (RETIRED) 2005-05-09 08:25:39 0000 -------
sparc done by eradicator, i'm no longer required here :)

------- Comment #10 From Sune Kloppenborg Jeppesen 2005-05-10 14:46:20 0000 -------
GLSA 200505-07

First Last Prev Next    No search results available      Search page      Enter new bug