I just went through all the CVEs recorded in pkgsrc as applying to tiff (ignoring those marked fixed with earlier versions) and this is the only one left:
https://nvd.nist.gov/vuln/detail/CVE-2018-10126 https://gitlab.com/libtiff/libtiff/-/issues/128 That's not meant as a complaint - it's a huge milestone given the history of tiff and CVEs.
signature.asc
Description: PGP signature
_______________________________________________ Tiff mailing list [email protected] https://lists.osgeo.org/mailman/listinfo/tiff
