For more details on the version bump, see: - https://gitlab.com/libtiff/libtiff/-/releases/v4.7.1 This bump includes the security fix for CVE-2025-8176, CVE-2025-8177 that were addressed in commit [1][2]. Also fixes the following vulnerabilities: - CVE-2024-13978 A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the file tools/tiff2pdf.c of the component fax2ps. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation appears to be difficult. The patch is named 2ebfffb0e8836bfb1cd7d85c059cd285c59761a4. It is recommended to apply a patch to fix this issue. For more information, see: - https://nvd.nist.gov//vuln/detail/CVE-2024-13978 - https://gitlab.com/libtiff/libtiff/-/commit/2ebfffb0e8836bfb1cd7d85c059cd285c59761a4 - CVE-2025-8961 A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be exploited. For more information, see: - https://nvd.nist.gov//vuln/detail/CVE-2025-8961 - https://gitlab.com/libtiff/libtiff/-/commit/0ac97aa7a5bffddd88f7cdbe517264e9db3f5bd5 - CVE-2025-9165 A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. For more information, see: - https://nvd.nist.gov//vuln/detail/CVE-2025-9165 - https://gitlab.com/libtiff/libtiff/-/commit/ed141286a37f6e5ddafb5069347ff5d587e7a4e0 This commit also updates the LICENSE.md hash file, which was updated upstream to include a historical license. See: https://gitlab.com/libtiff/libtiff/-/commit/a0b623c7809ea2aa4978d5d7b7bd10e519294c78 [1]b3974df966package/tiff: add patches to fix CVE-2025-8176 [2]3db725d71dpackage/tiff: add patch to fix CVE-2025-8177 Signed-off-by: Thomas Perale <thomas.perale@mind.be> [Julien: fix license hash] Signed-off-by: Julien Olivain <ju.o@free.fr>
6 lines
337 B
Plaintext
6 lines
337 B
Plaintext
# Locally computed after checking pgp signature
|
|
# https://download.osgeo.org/libtiff/tiff-4.7.1.tar.xz.sig
|
|
# with key: B1FA7D81EEB8E66399178B9733EBBFC47B3DD87D
|
|
sha256 b92017489bdc1db3a4c97191aa4b75366673cb746de0dce5d7a749d5954681ba tiff-4.7.1.tar.xz
|
|
sha256 0e27c2382d7b8147972bbb746e04059a1152c8d0fda9d03ef1399d1a433c4ade LICENSE.md
|