Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 27 Apr 2016 16:54:41 -0500 (CDT)
From: Bob Friesenhahn <bfriesen@...ple.dallas.tx.us>
To: oss-security@...ts.openwall.com
Subject: Re: 3 bugs refer to buffer overflow in in libtiff
 4.0.6

On Tue, 26 Apr 2016, Jodie Cunningham wrote:
>>
>> Running each poc file crashes thumbnail and bmp2tiff made with
>> AddressSanitizer in tiff-4.0.6. I have attached poc and log files .
>> ------------------
>> From Debug_Orz
>>
> Is there a patch upstream?

To my knowledge, none of the issues recently posted on this list have 
been addressed yet in libtiff.

It is always our priority to fix issues occuring in libtiff itself 
before addressing issues in the libtiff utilities.  Some of the 
libtiff maintainers care about only a few of the utilities.  We are 
all volunteers and available time is limited.

It is my intention to spend time addressing the libtiff utility issues 
(some of which might be due to issues in core libtiff) once I have 
addressed the remaining CVEs in GraphicsMagick.  Issues appearing to 
be due to problems in libtiff itself will get attention first.

Well-formulated source patches are welcomed for the issues.

Bob
-- 
Bob Friesenhahn
bfriesen@...ple.dallas.tx.us, http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.