Re: [Tiff] clarification on the fix status for new CVE-2022-3570?

2022-11-07 Thread Ellen Johnson
Thank you Bob for explaining more about libtiff and security fixes. Believe me, I feel libtiff developers' pain with CVEs, as we have a challenging time keeping up with all the CVE reports we get for third party libraries and cross-checking the NVD details with library bug reports and source

Re: [Tiff] clarification on the fix status for new CVE-2022-3570?

2022-11-07 Thread Bob Friesenhahn
On Mon, 7 Nov 2022, Ellen Johnson wrote: Thank you Kurt. And thank you to all the libtiff developers. Kurt, thanks for your suggestion about using libtiff from head as you do for Google and it would be great if we could do that too. However here at MathWorks our product security team

Re: [Tiff] clarification on the fix status for new CVE-2022-3570?

2022-11-07 Thread Ellen Johnson
Thank you Kurt. And thank you to all the libtiff developers. Kurt, thanks for your suggestion about using libtiff from head as you do for Google and it would be great if we could do that too. However here at MathWorks our product security team requires us to use official library releases.