2008.08.29 22:53 "[Tiff] Some security fixes from RHEL", by Even Rouault

2008.09.03 08:05 "Re: [Tiff] Some security fixes from RHEL", by Andrey Kiselev

On Tue, Sep 02, 2008 at 02:30:52AM +0400, Dmitry V. Levin wrote:

You may wish to have a look at patches applied in the libtiff package I maintain: http://git.altlinux.org/people/ldv/packages/?p=libtiff.git;a=tree

In particular, security related patches for 3.8.2 are: libtiff-3.8.2-google-CVE-2006-3459-3465.patch

libtiff-3.8.2-deb-tiffsplit-CVE-2006-2656.patch
libtiff-3.8.2-deb-tiff2pdf-CVE-2006-2193.patch
libtiff-3.8.2-apple-CVE-2008-2327.patch

Dmitry,

Thanks, the tiff2pdf and tiffsplit ones were missing from the our dev tree. I have applied them both in 3.9 and 4.0.

Best regards,

Andrey

--
Andrey V. Kiselev
ICQ# 26871517