I have also updated vcpkg to 4.4.0 in this PR:
https://github.com/microsoft/vcpkg/pull/24986

-----Original Message-----
From: Tiff <[email protected]> On Behalf Of Greg Troxel
Sent: 29 May 2022 14:00
To: Even Rouault <[email protected]>
Cc: [email protected]
Subject: Re: [Tiff] libtiff 4.4.0 is released


I have committed an update to pkgsrc of 4.4.0.

We have a database of CVEs and what versions they apply to.  With 4.4.0 and
me adjusting the entries to limit many of them to <4.4.0, only one CVE
remains in the database.

As far as I can tell this one is not resolved, but I didn't try the POC:

  https://nvd.nist.gov/vuln/detail/CVE-2018-10126
  http://bugzilla.maptools.org/show_bug.cgi?id=2786
  https://gitlab.com/libtiff/libtiff/-/issues/128

_______________________________________________
Tiff mailing list
[email protected]
https://lists.osgeo.org/mailman/listinfo/tiff

Reply via email to