Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 276339
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
libtiff-CVE-2009-2285.patch libtiff-CVE-2009-2285.patch patch Robert Buchholz 2009-07-03 08:55 0000 847 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 276339 depends on: Show dependency tree
Bug 276339 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2009-07-03 08:54 0000
CVE-2009-2285 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2285):
  Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2
  allows context-dependent attackers to cause a denial of service
  (crash) via a crafted TIFF image, a different vulnerability than
  CVE-2008-2327.

------- Comment #1 From Robert Buchholz 2009-07-03 08:55:52 0000 -------
Created an attachment (id=196475) [details]
libtiff-CVE-2009-2285.patch

Patch as applied in upstream HEAD, refreshed to 3.8.2 release. Note that
another patch has been applied to 3.9 branch but upstream considers this a
cleaner patch.

------- Comment #2 From Markus Meier 2009-07-04 19:27:31 0000 -------
bumped in cvs.

*tiff-3.8.2-r7 (04 Jul 2009)

  04 Jul 2009; Markus Meier <maekke@gentoo.org> +tiff-3.8.2-r7.ebuild,
  +files/tiff-3.8.2-CVE-2009-2285.patch:
  version bump wrt security bug #276339. this ebuild is based on
  tiff-3.8.2-r5.ebuild as opengl-support is currently broken in -r6.

------- Comment #3 From Stefan Behte 2009-07-04 20:54:56 0000 -------
Arches, please test and mark stable:
=media-libs/tiff-3.8.2-r7
Target keywords : "alpha amd64 arm hppa ia64 m68k ppc ppc64 s390 sh sparc x86"

------- Comment #4 From Jeroen Roovers 2009-07-06 03:03:20 0000 -------
Stable for HPPA.

------- Comment #5 From Christian Faulhammer 2009-07-06 18:05:56 0000 -------
x86 stable

------- Comment #6 From Brent Baude 2009-07-06 18:21:18 0000 -------
ppc64 done

------- Comment #7 From Brent Baude 2009-07-06 18:21:25 0000 -------
ppc done

------- Comment #8 From Raúl Porcel 2009-07-08 14:18:56 0000 -------
alpha/arm/ia64/m68k/s390/sh/sparc stable

------- Comment #9 From Markus Meier 2009-07-08 20:30:57 0000 -------
amd64 stable, all arches done.

------- Comment #10 From Robert Buchholz 2009-08-07 11:49:34 0000 -------
GLSA 200908-03

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug