Summary: | <media-libs/tiff-4.0.7: multiple vulnerabilities (CVE-2014-{8127,8128,8129,8130,9655},CVE-2015-1547) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | graphics+disabled |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.openwall.com/lists/oss-security/2015/01/24/15 | ||
Whiteboard: | A2 [glsa cve] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
![]() Further CVEs assigned in http://seclists.org/oss-sec/2015/q1/454 The following have been addressed in http://libtiff.maptools.org/v4.0.4beta.html CVE-2014-{8127,8128,8129} CVE-2014-9655 addressed in https://abi-laboratory.pro/tracker/changelog/libtiff/4.0.4/log.html CVE-2014-8130 can no longer be reproduced by upstream http://bugzilla.maptools.org/show_bug.cgi?id=2483 CVE-2015-1547 remains unfixed. (In reply to Aaron Bauman from comment #2) > CVE-2015-1547 remains unfixed. Fixed in 4.0.7, from https://bugzilla.redhat.com/show_bug.cgi?id=1190709#c3: > Considering above part of patch that fixes CVE-2014-9655 in tif_next.c from > commit https://github.com/vadz/libtiff/commit/40a5955cbf0df62b1f9e9bd7d9657b0070725d19 > fixes CVE-2015-1547 Added to existing GLSA request. This issue was resolved and addressed in GLSA 201701-16 at https://security.gentoo.org/glsa/201701-16 by GLSA coordinator Thomas Deutschmann (whissi). |