Your message dated Wed, 22 Jul 2026 18:50:00 +0000
with message-id <[email protected]>
and subject line Bug#1141320: fixed in tiff 4.7.0-3+deb13u3
has caused the Debian Bug report #1141320,
regarding tiff: CVE-2026-12912
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1141320: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141320
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: tiff
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for tiff.

CVE-2026-12912[0]:
| A flaw was found in libtiff. A remote attacker could exploit this
| vulnerability by providing a specially crafted PixarLog-compressed
| TIFF image. This issue occurs when decoding Pixarlog codec images
| with the PIXARLOGDATAFMT_8BITABGR output format and a specific
| stride value, leading to a heap-based buffer overflow. This could
| potentially result in arbitrary code execution or a denial of
| service (DoS).

https://gitlab.com/libtiff/libtiff/-/work_items/824
https://gitlab.com/libtiff/libtiff/-/merge_requests/873
https://gitlab.com/libtiff/libtiff/-/commit/ba2b04b114c5dd945107ccc613cedfcca3af73bb
 (v4.7.2rc2)
https://gitlab.com/libtiff/libtiff/-/commit/51fa6dfe93f20da0d38f079fbc61c7c960bcbc16
 (v4.7.2rc2)

https://gitlab.com/libtiff/libtiff/-/work_items/828
https://gitlab.com/libtiff/libtiff/-/merge_requests/883
https://gitlab.com/libtiff/libtiff/-/commit/f9bda11bf2fc819b971517582666d56f18b1bc3f
 (v4.7.2rc2)
https://gitlab.com/libtiff/libtiff/-/commit/90601d9a23382d98f3695ec14441145c37a77574
 (v4.7.2rc2)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-12912
    https://www.cve.org/CVERecord?id=CVE-2026-12912

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: tiff
Source-Version: 4.7.0-3+deb13u3
Done: Salvatore Bonaccorso <[email protected]>

We believe that the bug you reported is fixed in the latest version of
tiff, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated tiff package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 10 Jul 2026 16:34:09 +0200
Source: tiff
Architecture: source
Version: 4.7.0-3+deb13u3
Distribution: trixie-security
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 1141320
Changes:
 tiff (4.7.0-3+deb13u3) trixie-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * Address heap-based buffer overflow in pixarlog (CVE-2026-12912)
     (Closes: #1141320)
     - pixarlog: fix heap-buffer-overflow in 8BITABGR decode with stride 3
     - pixarlog: add comment explaining 4-byte advance in ABGR decode
     - pixarlog: complete ABGR bounds check for multi-row strip decoding
     - pixarlog: error out on invalid ABGR output buffer sizes
Checksums-Sha1:
 f3d03d9c9d01c0dde179979004ce2d29889acdbc 2442 tiff_4.7.0-3+deb13u3.dsc
 7189a4f61dbaa8e9bc60ee72c63e335be7008d62 28212 
tiff_4.7.0-3+deb13u3.debian.tar.xz
 caa0302d83539ecebacf9de9e8c462eca49a80d9 6300 
tiff_4.7.0-3+deb13u3_source.buildinfo
Checksums-Sha256:
 51cdbd32322b5d35ef35677ace1cb7cd6591325da4ecd470ec6ccefab47d6a29 2442 
tiff_4.7.0-3+deb13u3.dsc
 c0cbcb717e20a69964bfa7471cbb0137dd39a451434932972bc7fbcdb86345f8 28212 
tiff_4.7.0-3+deb13u3.debian.tar.xz
 12b3f217f1089247d721d3627698106b9b759ac4dce652d28c18afc1193ec0e8 6300 
tiff_4.7.0-3+deb13u3_source.buildinfo
Files:
 7a3f9a3291c5472eca3d88db16fe2a17 2442 libs optional tiff_4.7.0-3+deb13u3.dsc
 abfac5faff6c0a86a31a97e79da7046d 28212 libs optional 
tiff_4.7.0-3+deb13u3.debian.tar.xz
 a2c060cbb8bcdd2c85b68722eed44bca 6300 libs optional 
tiff_4.7.0-3+deb13u3_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmpb48hfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89E7G8P/RVbYOELKkX4YffwXdcY/Uke6Oi5CXCr
Bp3kRH/jECZLSHMKtWhBpeU3k04MPqCYZUKTimboVZLmfn/1KhmYL3XoRRrUy0qD
qN+CxS8PaVIydpL12BNpsAOAPQKrH5Of0rfbssqUeycL1+qfyZrzdQD6YTCSwMlX
vvc5fx12angNIS9YijA9PMYVbSH99vVy+HZkKnnECnjOc8NHXbSiGzKk52fz242t
TlxzmW+Cgtb8n6RXAOd+IPnDjXIimnuaJY9wJl+40LvB6miDFBR0zD25IbmFdAPG
l7W3tfS3LsY4BaL/6+3RrxSxBINZFuUWLZs/pWrcbAP3QaCPAu5ZKAUFIHJafSO/
W536VbNW5Og4qf71m1IRONL+xD/5/l78jKYbacfgMFDs8tCCqkvJty4Mf0z49MmQ
2zezGfuJTXFuMROQNJyZeC0XPMZMc77OW1M+5nTkC88GaIOAkiVP41FpLiehoMXd
YSTCIiGGemMKFrEN46URoGQrAjpsY5viQdv3K86w2H192Vizzk8r15lo790tvPnp
r8MNC6HopI/ZQmkZ6P2wPoLWFVTS8yMxIh5h5/D4aA288ttStv5HVaB4NfZMKbur
h6XTRQ0zsew8dJ5odjtXevG98I9EKvVS89QPD5cNVP4et0N6gKv+Z4C9GgKhvo5o
7UvUbcaR18Du
=NVhi
-----END PGP SIGNATURE-----

Attachment: pgpqfIJYGDG2h.pgp
Description: PGP signature


--- End Message ---

Reply via email to