• [SECURITY] [DSA 4670-1] tiff security update

    From Salvatore Bonaccorso@1:229/2 to All on Wed Apr 29 23:20:01 2020
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4670-1 [email protected] https://www.debian.org/security/ Salvatore Bonaccorso
    April 29, 2020 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : tiff
    CVE ID : CVE-2018-12900 CVE-2018-17000 CVE-2018-17100 CVE-2018-19210
    CVE-2019-7663 CVE-2019-14973 CVE-2019-17546
    Debian Bug : 902718 908778 909038 913675 934780

    Several vulnerabilities have been found in the TIFF library, which may
    result in denial of service or the execution of arbitrary code if
    malformed image files are processed.

    For the oldstable distribution (stretch), these problems have been fixed
    in version 4.0.8-2+deb9u5.

    We recommend that you upgrade your tiff packages.

    For the detailed security status of tiff please refer to its security
    tracker page at:
    https://security-tracker.debian.org/tracker/tiff

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl6p7S1fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0QRww/9Eg0o7jBO3bXuXYcN1VqUZA4ZllTf/AOIsASzAcx6P1XBk/mrcMtsNehh VY0sXmdw2AN+OInTdcMrRYvMogeKVHhgyaTJScVfaKANFX4Imy0GKSTa028amdLi 8D1Pj2zc54jQ2crSkkempXAjce+Ut4yrjow5xRY1mhNQDEKeibAx9Cmsra0YThFr VN37zGzXIA4K3cM4uZ5Pr3AWvKKlJDHHzEB7wx8FHhP0K7nnatOQDCEHfPTrEfL7 +ILhVauBPD+nj9+umZh6bTf6eiBlTL+WsTReR6Tcgfgg7YtLHY32xSD1e/anRK7C eGsWDsHrpYlqxISGDz5KI7sQt1yvUIBuIPoYMIFRegJqHPU89r7KuSjhnCse29z3 l+HdPVQyobPZZhuAyTXIS9Ba1H8zkCwWhUMetsnU1cANKro4K4VnMXlrKsQn2zL9 aiuKKSpBajnCq9Iw4e5MNGtlhO8N9i1bg3gkQoDU9ODm5wiW2AGEfhUkefY9c4Vg WZzuwnfZ1sthaSNWHeW/fxl2wwEJHOmPiFy1QDC1m0WGtgV2J3BhT6xCRvmmislB PRTVJT3nqwG1MCvEplPMLhvQ7b+SWguNijLukPPIgMmSVwMYgbMMAxrjGqHYQS/d gt+rgrqUZcJ2LT77OZnGSMwU48XOHGaQAboRG9k3R64ptX26OTg=
    =0x/q
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)