Re: update: graphics/tiff: CVE-2012-1173 libtiff: Heap-buffer overflow

2012-04-09 Thread Christian Weisgerber
Sébastien Marie semarie-open...@latrappe.fr wrote: The current version of graphics/tiff (3.9.5) in ports seems to be vulnerable to CVE-2012-1173, a heap-buffer overflow. Upstream information and patch: http://bugzilla.maptools.org/show_bug.cgi?id=2369 Thanks, fix applied. -- Christian

update: graphics/tiff: CVE-2012-1173 libtiff: Heap-buffer overflow

2012-04-07 Thread Sébastien Marie
Hi, The current version of graphics/tiff (3.9.5) in ports seems to be vulnerable to CVE-2012-1173, a heap-buffer overflow. Upstream information and patch: http://bugzilla.maptools.org/show_bug.cgi?id=2369 Others informations: http://seclists.org/oss-sec/2012/q2/31