Information on source package tiff

Available versions

ReleaseVersion
squeeze, squeeze3.9.4-5+squeeze4
wheezy4.0.1-5
sid4.0.1-6

Open issues

BugDescription
CVE-2010-4665Integer overflow in the ReadDirectory function in tiffdump.c in ...
TEMP-0668087-2BC9BCtiff electric fence crashes

Open unimportant issues

BugDescription
CVE-2008-1586ImageIO in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod ...
CVE-2010-2595The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in ...
CVE-2010-2596The OJPEGPostDecode function in tif_ojpeg.c in LibTIFF 3.9.0 and ...
CVE-2010-2597The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 ...
CVE-2010-2598LibTIFF in Red Hat Enterprise Linux (RHEL) 3 on x86_64 platforms, as ...
CVE-2010-2630The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly ...
CVE-2010-2631LibTIFF 3.9.0 ignores tags in certain situations during the first ...

Resolved issues

BugDescription
CVE-2004-0803Multiple vulnerabilities in the RLE (run length encoding) decoders for ...
CVE-2004-0804Vulnerability in tif_dirread.c for libtiff allows remote attackers to ...
CVE-2004-0886Multiple integer overflows in libtiff 3.6.1 and earlier allow remote ...
CVE-2004-1183Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier ...
CVE-2004-1307Integer overflow in the TIFFFetchStripThing function in tif_dirread.c ...
CVE-2004-1308Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff ...
CVE-2005-1544Stack-based buffer overflow in libTIFF before 3.7.2 allows remote ...
CVE-2005-2452libtiff up to 3.7.0 allows remote attackers to cause a denial of ...
CVE-2006-0405The TIFFFetchShortPair function in tif_dirread.c in libtiff 3.8.0 ...
CVE-2006-2024Multiple vulnerabilities in libtiff before 3.8.1 allow ...
CVE-2006-2025Integer overflow in the TIFFFetchData function in tif_dirread.c for ...
CVE-2006-2026Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows ...
CVE-2006-2120The TIFFToRGB function in libtiff before 3.8.1 allows remote attackers ...
CVE-2006-2193Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff ...
CVE-2006-2656Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 ...
CVE-2006-3459Multiple stack-based buffer overflows in the TIFF library (libtiff) ...
CVE-2006-3460Heap-based buffer overflow in the JPEG decoder in the TIFF library ...
CVE-2006-3461Heap-based buffer overflow in the PixarLog decoder in the TIFF library ...
CVE-2006-3462Heap-based buffer overflow in the NeXT RLE decoder in the TIFF library ...
CVE-2006-3463The EstimateStripByteCounts function in TIFF library (libtiff) before ...
CVE-2006-3464TIFF library (libtiff) before 3.8.2 allows context-dependent attackers ...
CVE-2006-3465Unspecified vulnerability in the custom tag support for the TIFF ...
CVE-2008-2327Multiple buffer underflows in the (1) LZWDecode, (2) LZWDecodeCompat, ...
CVE-2009-2285Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 ...
CVE-2009-2347Multiple integer overflows in inter-color spaces conversion tools in ...
CVE-2009-5022Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in ...
CVE-2010-1411Multiple integer overflows in the Fax3SetupState function in ...
CVE-2010-2065Integer overflow in the TIFFroundup macro in LibTIFF before 3.9.3 ...
CVE-2010-2067Stack-based buffer overflow in the TIFFFetchSubjectDistance function ...
CVE-2010-2233tif_getimage.c in LibTIFF 3.9.0 and 3.9.2 on 64-bit platforms, as used ...
CVE-2010-2443The OJPEGReadBufferFill function in tif_ojpeg.c in LibTIFF before ...
CVE-2010-2481The TIFFExtractData macro in LibTIFF before 3.9.4 does not properly ...
CVE-2010-2482LibTIFF 3.9.4 and earlier does not properly handle an invalid ...
CVE-2010-2483The TIFFRGBAImageGet function in LibTIFF 3.9.0 allows remote attackers ...
CVE-2010-3087LibTIFF before 3.9.2-5.2.1 in SUSE openSUSE 11.3 allows remote ...
CVE-2011-0191Buffer overflow in LibTIFF 3.9.4 and possibly other versions, as used ...
CVE-2011-0192Buffer overflow in Fax4Decode in LibTIFF 3.9.4 and possibly other ...
CVE-2011-1167Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in ...
CVE-2012-1173

Security announcements

DSADescription
DSA-2447-1tiff - integer overflow
DSA-2256-1tiff - buffer overflow
DSA-2210-1tiff - several
DSA-2210-1tiff - several
DSA-2084-1tiff - arbitrary code execution
DSA-1835-1tiff - several vulnerabilities
DSA-1835-1tiff - several vulnerabilities
DSA-1632-1tiff - arbitrary code execution
DSA-1137-1tiff - several vulnerabilities
DSA-1091-1tiff - buffer overflows
DSA-1091-1tiff - buffer overflows
DSA-1078-1tiff - out-of-bounds read
DSA-1054-1tiff - several vulnerabilities
DSA-1054-1tiff - several vulnerabilities
DSA-755-1tiff - buffer overflow
DSA-626-1tiff - unsanitised input
DSA-617-1libtiff - insufficient input validation
DSA-567-1tiff - heap overflows

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Source (SVN)