Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 91604 - kde-base/kdegraphics Vulnerabilities in included tiff
Summary: kde-base/kdegraphics Vulnerabilities in included tiff
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL: http://bugzilla.remotesensing.org/sho...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-05-05 13:06 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2006-12-27 01:18 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-05 13:06:26 UTC
New vulnerabilities were discovered in libtiff (bug #91584).

I'm not sure wether any of versions in Portage still include their private libtiff copy, but filing this to check.

Carlo please advise.
Comment 1 Carsten Lohrke (RETIRED) gentoo-dev 2005-05-05 17:00:44 UTC
kdegraphics-3.2 includes libtiffax, but is not affected. kde-3.3/4 use media-libs/tiff. We're safe as soon as libtiff is fixed. :) 
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-05 22:28:05 UTC
3.2 is not the latest stable on any arches? AFAIR only 3.3 was fixed with the last tiff vulnerability.
Comment 3 Carsten Lohrke (RETIRED) gentoo-dev 2005-05-06 05:58:17 UTC
<=kdegraphics-3.3.1 include libtiffax
>=kdegraphics-3.3.2 do not

The fix of the last tiff vulnerability was the update to KDE 3.3.2, but this issue wouldn't affect kdegraphics-3.3.1 either.


>3.2 is not the latest stable on any arches?

I don't think so, but it is not affected anyways. libtiffax does not include the vulnerable code. I guess it's just too old.
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-06 06:30:30 UTC
Thx for the clarification Carlo.