Re: [SECURITY] tiff

2013-04-10 Thread Yaakov (Cygwin/X)
On 2012-12-15 23:06, Yaakov (Cygwin/X) wrote: Chuck, Security vulnerabilities have been announced for the tiff package. Please update tiff to 3.9.7 together with this patchset ASAP: http://pkgs.fedoraproject.org/cgit/libtiff.git/tree/?h=f17

Re: [SECURITY] tiff, libpng, automake

2012-08-15 Thread Peter Rosin
On 2012-08-15 02:30, Yaakov (Cygwin/X) wrote: On Tue, 2012-08-14 at 22:05 +0200, Corinna Vinschen wrote: Chuck? Ping 2? If you don't reply I guess we have to assume you're not with us anymore. Which would be too bad. Indeed. :-( Dito. On Aug 3 09:58, Corinna Vinschen wrote: On Jul

Re: [SECURITY] tiff, libpng

2012-08-14 Thread Corinna Vinschen
Chuck? Ping 2? If you don't reply I guess we have to assume you're not with us anymore. Which would be too bad. On Aug 3 09:58, Corinna Vinschen wrote: Chuck? Ping? Are you still with us? On Jul 23 16:48, Yaakov (Cygwin/X) wrote: Chuck, Security vulnerabilities are accumulating

Re: [SECURITY] tiff, libpng, automake

2012-08-14 Thread Yaakov (Cygwin/X)
On Tue, 2012-08-14 at 22:05 +0200, Corinna Vinschen wrote: Chuck? Ping 2? If you don't reply I guess we have to assume you're not with us anymore. Which would be too bad. Indeed. :-( On Aug 3 09:58, Corinna Vinschen wrote: On Jul 23 16:48, Yaakov (Cygwin/X) wrote: Chuck,

Re: [SECURITY] tiff, libpng

2012-08-03 Thread Corinna Vinschen
Chuck? Ping? Are you still with us? On Jul 23 16:48, Yaakov (Cygwin/X) wrote: Chuck, Security vulnerabilities are accumulating for the tiff package (CVE-2011-0192, CVE-2011-1167, CVE-2012-1173, CVE-2012-2088, CVE-2012-2113, CVE-2012-3401). This can be fixed by updating to 3.9.6 and

[SECURITY] tiff, libpng

2012-07-23 Thread Yaakov (Cygwin/X)
Chuck, Security vulnerabilities are accumulating for the tiff package (CVE-2011-0192, CVE-2011-1167, CVE-2012-1173, CVE-2012-2088, CVE-2012-2113, CVE-2012-3401). This can be fixed by updating to 3.9.6 and applying the four patches found here:

Re: SECURITY: tiff

2011-04-04 Thread Charles Wilson
On 4/3/2011 4:17 PM, Yaakov (Cygwin/X) wrote: Security vulnerabilities have been announced in the tiff package. Thanks for the heads up. I'll update later this week. -- Chuck

SECURITY: tiff

2011-04-03 Thread Yaakov (Cygwin/X)
Chuck, Security vulnerabilities have been announced in the tiff package. The remedy is to update to the latest 3.9.4 release AND apply the following patches: http://pkgs.fedoraproject.org/gitweb/?p=libtiff.git;a=blob_plain;f=libtiff-CVE-2011-0192.patch

Re: SECURITY: tiff

2006-07-19 Thread Yaakov S (Cygwin Ports)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Yaakov S (Cygwin Ports) wrote: Yaakov S (Cygwin Ports) wrote: Multiple vulnerabilities, ranging from integer overflows and NULL pointer dereferences to double frees, were reported in libTIFF. And now, there's more: A buffer overflow has been

Re: SECURITY: tiff

2006-07-12 Thread Yaakov S (Cygwin Ports)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Yaakov S (Cygwin Ports) wrote: Multiple vulnerabilities, ranging from integer overflows and NULL pointer dereferences to double frees, were reported in libTIFF. And now, there's more: A buffer overflow has been found in the t2p_write_pdf_string

Re: SECURITY: tiff

2006-07-12 Thread Yaakov S (Cygwin Ports)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Yaakov S (Cygwin Ports) wrote: Solution: update to 3.8.2 and apply the following patches: http://www.gentoo.org/cgi-bin/viewcvs.cgi/*checkout*/media-libs/tiff/files/tiff-3.8.2-tiffsplit.patch

Re: SECURITY: tiff

2006-06-14 Thread Yaakov S (Cygwin Ports)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Yaakov S (Cygwin Ports) wrote: Multiple vulnerabilities, ranging from integer overflows and NULL pointer dereferences to double frees, were reported in libTIFF. Solution: Update to =3.8.1. More information:

SECURITY: tiff

2006-05-30 Thread Yaakov S (Cygwin Ports)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Multiple vulnerabilities, ranging from integer overflows and NULL pointer dereferences to double frees, were reported in libTIFF. Solution: Update to =3.8.1. More information: http://www.gentoo.org/security/en/glsa/glsa-200605-17.xml