[SECURITY] [DLA 1378-1] tiff3 security update

2018-05-13 Thread Hugo Lefeuvre
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tiff3 Version: 3.9.6-11+deb7u11 CVE ID : CVE-2018-8905 Debian Bug : 893806 A heap-based buffer overflow was discovered in the LZWDecodeCompat function in tif_lzw.c (LibTIFF 4.0.9 and earlier). This vulnerability

[SECURITY] [DLA 1377-1] tiff security update

2018-05-13 Thread Hugo Lefeuvre
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tiff Version: 4.0.2-6+deb7u20 CVE ID : CVE-2018-8905 Debian Bug : 893806 A heap-based buffer overflow was discovered in the LZWDecodeCompat function in tif_lzw.c (LibTIFF 4.0.9 and earlier). This vulnerability