<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>75213</bug_id>
          
          <creation_ts>2004-12-21 10:42 0000</creation_ts>
          <short_desc>media-libs/tiff: version 3.7.1 fixes integer overflows</short_desc>
          <delta_ts>2005-01-12 17:46:57 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>A2 [glsa] koon</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>75423</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>koon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>nerdboy@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-12-21 10:42:44 0000</bug_when>
            <thetext>Two iDEFENSE advisories should go out soon :

- libtiff STRIPOFFSETS Integer Overflow Vulnerability
- LibTIFF Directory Entry Count Integer Overflow Vulnerability

Both are fixed in upstream release 3.7.1

nerdboy: This is still semi-public, so please don&apos;t talk about it (should be public in a few hours) but please submit a new 3.7.1 ebuild silently referencing this bug.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-12-21 11:04:05 0000</bug_when>
            <thetext>Note to self, this might also affect :

- PDFLib (includes modified libtiff)
- kfax (includes libtiff code)
- xv (might need to be rebuilt with a new libtiff.a)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>nerdboy@gentoo.org</who>
            <bug_when>2004-12-21 14:41:02 0000</bug_when>
            <thetext>Okay, new ebuild going in portage now.  Should I remove the old ones and mark the 
new 3.7.1 version stable on all arches?  I&apos;m about to commit it as ~arch, and 
I&apos;ll be right back after I go turn the grades in...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lewk@gentoo.org</who>
            <bug_when>2004-12-21 14:51:25 0000</bug_when>
            <thetext>This issue is now public

     http://www.idefense.com/application/poi/display?id=174

arches, please mark stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kingtaco@gentoo.org</who>
            <bug_when>2004-12-21 16:55:22 0000</bug_when>
            <thetext>stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2004-12-22 05:01:10 0000</bug_when>
            <thetext>sparc stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-12-22 07:28:11 0000</bug_when>
            <thetext>Hmm I think we&apos;ll hold on this one a little.

Apparently the &apos;libtiff STRIPOFFSETS Integer&apos; is a subset of CAN-2004-0886 that has already been fixed by GLSA 200410-11.

The other one would not be exploitable except for a crash. However there is another one coming.

Removing arches for the time being, as we probably will commit a -r1 with a patch.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>nerdboy@gentoo.org</who>
            <bug_when>2004-12-22 11:12:18 0000</bug_when>
            <thetext>I&apos;m not sure how to link these in bugzilla, but this bug 75316 seems to have been 
introduced with the new 3.7.1 release.  I&apos;m still researching it, so that&apos;s all 
I know so far.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-12-23 02:49:06 0000</bug_when>
            <thetext>Test image for the &quot;LibTIFF Directory Entry Count Integer Overflow&quot; Vulnerability
ftp://ftp.altlinux.org/pvt/people/ldv/1x1.tiff</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-12-27 09:10:23 0000</bug_when>
            <thetext>LibTIFF Directory Entry Count Integer Overflow Vulnerability is CAN-2004-1308, see DSA 617-1.

If work doesn&apos;t progress on the other libtiff-related vuln, we&apos;ll probably go on and release an updated tiff with only this one. Steve, you might prefer us to wait so that you get time to sort out bug 75316 before we start asking arches to test again. Keep us posted.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-01-01 11:31:52 0000</bug_when>
            <thetext>No progress on the other security issue, better unblocking this one.

Calling back arches to test and mark stable. Please pay special attention to possible transparency issues to see if you reproduce bug 75316.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>nerdboy@gentoo.org</who>
            <bug_when>2005-01-01 20:36:09 0000</bug_when>
            <thetext>The transparency bug has bitten at least two windowmaker users (confirmed via 
independent tools) so if you can, it might be better to wait and get it all 
sorted out at once.  I&apos;m not sure if transparent faxes are a big deal, but 
there are probably other applications with a bigger need for transparency 
than security is a risk.  Or we can do it piece-meal...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2005-01-02 06:44:39 0000</bug_when>
            <thetext>stable on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2005-01-02 08:00:21 0000</bug_when>
            <thetext>Stable on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>nerdboy@gentoo.org</who>
            <bug_when>2005-01-02 18:21:04 0000</bug_when>
            <thetext>Fixes for both 75316 and 75423 are in -r1.  I guess everyone gets to test and 
mark stable as you can.  Thanks in advance.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-01-03 00:29:28 0000</bug_when>
            <thetext>Arches: please test and mark 3.7.1-r1 stable. It&apos;s just 3.7.1 + a bugfix on the transparency issue and a fix on the tiffdump utility.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2005-01-03 00:52:49 0000</bug_when>
            <thetext>stable on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>josejx@gentoo.org</who>
            <bug_when>2005-01-03 05:08:36 0000</bug_when>
            <thetext>Tested and marked ppc stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-01-03 06:33:33 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tester@gentoo.org</who>
            <bug_when>2005-01-03 21:26:30 0000</bug_when>
            <thetext>x86 there</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hardave@gentoo.org</who>
            <bug_when>2005-01-04 01:03:36 0000</bug_when>
            <thetext>Stable on mips.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2005-01-04 02:34:05 0000</bug_when>
            <thetext>Stable on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>eradicator@gentoo.org</who>
            <bug_when>2005-01-04 04:47:58 0000</bug_when>
            <thetext>stable amd64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>j4rg0n@gentoo.org</who>
            <bug_when>2005-01-04 18:12:28 0000</bug_when>
            <thetext>Stable ppc-macos.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-01-05 14:08:42 0000</bug_when>
            <thetext>GLSA 200501-06
arm hppa ia64 s390 : please remember to mark stable to benefit from GLSA.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>