Package: tiff Version: 4.7.0-3+deb13u3 Severity: grave Tags: security Hi Team,
I am reporting an unresolved CVE affecting the tiff source package (specifically flagging libtiff6, libtiff-dev, and libtiffxx6 binary packages) on Debian Trixie (Debian 13), identified via a Prisma scanner. * CVE-2026-52490 (Critical) Notes: The vulnerable code (tiffcrop.c, process_command_opts()) belongs to libtiff-tools. While we don't install the tools binary, the library versions are still flagged due to the shared source version. This is already fixed upstream (v4.7.2rc2) and is present in Debian unstable (4.7.2-1). Could you advise on when this fix is expected to transition into Trixie? Regards, Joshua Aldwin L. Samonte Software Prod & Plat Eng Specialist Advanced Technology Centers in the Philippines *: [email protected]<mailto:[email protected]> ________________________________ This message is for the designated recipient only and may contain privileged, proprietary, or otherwise confidential information. If you have received it in error, please notify the sender immediately and delete the original. Any other use of the e-mail by you is prohibited. Where allowed by local law, electronic communications with Accenture and its affiliates, including e-mail and instant messaging (including content), may be scanned by our systems for the purposes of information security, AI-powered support capabilities, and assessment of internal compliance with Accenture policy. Your privacy is important to us. Accenture uses your personal data only in compliance with data protection laws. For further information on how Accenture processes your personal data, please see our privacy statement at https://www.accenture.com/us-en/privacy-policy. ______________________________________________________________________________________ www.accenture.com

