lp:debian/squeeze/tiff

Created by James Westby and last modified
Get this branch:
bzr branch lp:debian/squeeze/tiff
Members of Ubuntu branches can upload to this branch. Log in for directions.

Related bugs

Related blueprints

Branch information

Owner:
Ubuntu branches
Status:
Development

Recent revisions

19. By Jay Berkenbilt <email address hidden>

* Incorporated fixes to security issues CVE-2013-4231, CVE-2013-4232.
  (Closes: #719303)
* Incorporated fix to CVE-2013-4244.

18. By Jay Berkenbilt <email address hidden>

Add fix for CVE-2012-5581, reimplementing DOTRANGE handling to make it
safer. Thanks to Red Hat security team for backporting the fix.

17. By Moritz Muehlenhoff <email address hidden>

CVE-2012-1173

16. By Jay Berkenbilt <email address hidden>

Redo CVE-2011-0192 to fix regression. (Closes: #630042)

15. By Jay Berkenbilt <email address hidden>

Incorporated fix to CVE-2010-3087, a potential denial of service
exploitable with a specially crafted TIFF file. (Closes: #600188)

14. By Jay Berkenbilt <email address hidden>

Incorporated fix to CVE-2010-2483, "fix crash on OOB reads in
putcontig8bitYCbCr11tile". (Closes: #595064)

13. By Jay Berkenbilt <email address hidden>

Incorporated patch to fix CVE-2010-2233, which fixes a specific
failure of tif_getimage on 64-bit platforms.

12. By Jay Berkenbilt <email address hidden>

New upstream release

11. By Kees Cook

* SECURITY UPDATE: arbitrary code execution via multiple integer
  overflows. Backported upstream fixes:
  - debian/patches/CVE-2010-1411.patch
  - debian/patches/CVE-2010-2065.patch
  - debian/patches/CVE-2010-2067.patch
  - debian/patches/fix-64bit-flip.patch

10. By Jay Berkenbilt <email address hidden>

* Depend on libjpeg-dev instead of libjpeg62-dev. (Closes: #569242)
* Change source format to '3.0 (quilt)'
* Update standards version to 3.8.4. No changes required.

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
This branch contains Public information 
Everyone can see this information.

Subscribers