Bob Friesenhahn <[email protected]> writes: > The change-set you referred to is an attempt to solve a weakness in libtiff > which has existed since libtiff was invented (and is common to libraries > supporting compressed files). > > There has recently been an overwhelming flurry of libtiff bug/security > reports and a similarly large number of proposed change-sets. At least one > change-set purports to solve the common reason for many security reports, > which is integer value overflow.
I would like to hear your opinion about whether the issues and proposed changes are LLM generated, and what you think of their quality. > It is safest to assume that the next libtiff release will occur when it is > ready. I wonder then, as a packager, should I: Extract a patch from 4.7.1 to HEAD and apply that, calling it e.g. 4.7.1.50 and make that available to users? Just take the one commit Even points to, knowing that it's not really sensible, but as easier than explaining to people why they shouldn't be upset about CVE numbers. Repeat as necessary when CVEs are published. Do nothing for now, and when 4.7.2 comes out, with me not expecting it, update to it. Something else? _______________________________________________ Tiff mailing list [email protected] https://lists.osgeo.org/mailman/listinfo/tiff
