Hi,
I see 3 options:
- MathWorks finally creates a in-house policy abut how to properly
engage with the libtiff community that resists to staff turn-over
- MathWorks finally takes over libtiff mainternship to stop the bleeding
CVE hemoragy and publish a release after each fix is committed to master
- MathWorks creates its own CVE-free libtiff fork
I let you pick up your poison. But we are April 1st so I'm confident
your request is just an April fool
Cheeers
Even
Le 01/04/2026 à 08:58, Gayathri Venkat via Tiff a écrit :
Hello Team,
I am Gayathri, a developer at MathWorks. I believe in past you have
worked with some of the MathWorks developers.
At MathWorks, we are currently using libTIFF version 4.7.1, and we
recently became aware of a third‑party security vulnerability
(CVE‑2026‑4775). Additional details about this issue can be found
here: https://nvd.nist.gov/vuln/detail/CVE-2026-4775
Could you please let us know if there are any plans to release a new
version that addresses this vulnerability?
Thank you very much for your time and assistance.
Thanks & Regards,
Gayathri
_______________________________________________
Tiff mailing list
[email protected]
https://lists.osgeo.org/mailman/listinfo/tiff
--
http://www.spatialys.com
My software is free, but my time generally not.
_______________________________________________
Tiff mailing list
[email protected]
https://lists.osgeo.org/mailman/listinfo/tiff