oss-sec mailing list archives
Re: 3 bugs refer to buffer overflow in in libtiff 4.0.6
From: Bob Friesenhahn <bfriesen () simple dallas tx us>
Date: Wed, 27 Apr 2016 16:54:41 -0500 (CDT)
On Tue, 26 Apr 2016, Jodie Cunningham wrote:
Running each poc file crashes thumbnail and bmp2tiff made with AddressSanitizer in tiff-4.0.6. I have attached poc and log files . ------------------ From Debug_OrzIs there a patch upstream?
To my knowledge, none of the issues recently posted on this list have been addressed yet in libtiff.
It is always our priority to fix issues occuring in libtiff itself before addressing issues in the libtiff utilities. Some of the libtiff maintainers care about only a few of the utilities. We are all volunteers and available time is limited.
It is my intention to spend time addressing the libtiff utility issues (some of which might be due to issues in core libtiff) once I have addressed the remaining CVEs in GraphicsMagick. Issues appearing to be due to problems in libtiff itself will get attention first.
Well-formulated source patches are welcomed for the issues. Bob -- Bob Friesenhahn bfriesen () simple dallas tx us, http://www.simplesystems.org/users/bfriesen/ GraphicsMagick Maintainer, http://www.GraphicsMagick.org/
Current thread:
- 3 bugs refer to buffer overflow in in libtiff 4.0.6 PXO???? (Apr 26)
- Re: 3 bugs refer to buffer overflow in in libtiff 4.0.6 Jodie Cunningham (Apr 26)
- ?????? [oss-security] 3 bugs refer to buffer overflow in in libtiff 4.0.6 PXO???? (Apr 27)
- Re: 3 bugs refer to buffer overflow in in libtiff 4.0.6 Bob Friesenhahn (Apr 27)
- Re: 3 bugs refer to buffer overflow in in libtiff 4.0.6 cve-assign (Jun 06)
- Re: 3 bugs refer to buffer overflow in in libtiff 4.0.6 Jodie Cunningham (Apr 26)