This bug was fixed in the package tiff - 4.7.1-2ubuntu1
---------------
tiff (4.7.1-2ubuntu1) stonking; urgency=medium
* Merge from Debian unstable (LP: #2153363). Remaining changes:
- Don't build with LERC on i386 because it requires numpy (Closes: #1017958)
* Drop Changes:
- d/p/CVE-2025-8176.patch: fix heap use-after-free in tiffmedian
[Fixed in 4.7.1]
- d/p/CVE-2025-8534.patch: tiff2ps: check return of TIFFGetFiled() to fix
[Fixed in 4.7.1]
- d/p/CVE-2025-8961.patch: Add _TIFFfree and extra read_buff check
in tools/tiffcrop.c.
[Fixed in 4.7.1]
- d/p/CVE-2025-9165.patch: Add TIFFClose in tools/tiffcmp.c.
[Fixed in 4.7.1]
- d/p/CVE-2025-9900.patch: Add img->height and img->width checks
in libtiff/tif_getimage.c.
[Fixed in 4.7.1]
tiff (4.7.1-2) unstable; urgency=high
* Backport security fix for CVE-2026-4775, signed integer overflow
vulnerability in putcontig8bitYCbCr44tile() (closes: #1132632).
tiff (4.7.1-1) unstable; urgency=medium
* New upstream release.
* Update libtiff6 symbols.
tiff (4.7.0-5) unstable; urgency=high
* Backport security fix for CVE-2025-8961, double free and memory leak in
the tiffcrop tool (closes: #1111317).
* Update watch file.
* Update Standards-Version to 4.7.2 .
tiff (4.7.0-4) unstable; urgency=high
* Backport security fix for CVE-2025-9165, tiffcmp memory leak when second
file cannot be opened (closes: #1111878).
* Backport security fix for CVE-2024-13978, potential division-by-zero in
the tiff2pdf tool (closes: #1111323).
* Fix fax2ps regression where TIFFTAG_FAXFILLFUNC is being used rather than
an output buffer.
-- Simon Poirier <[email protected]> Thu, 21 May 2026
11:46:25 -0400
** Changed in: tiff (Ubuntu)
Status: In Progress => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2024-13978
** CVE added: https://cve.org/CVERecord?id=CVE-2025-8176
** CVE added: https://cve.org/CVERecord?id=CVE-2025-8534
** CVE added: https://cve.org/CVERecord?id=CVE-2025-8961
** CVE added: https://cve.org/CVERecord?id=CVE-2025-9165
** CVE added: https://cve.org/CVERecord?id=CVE-2025-9900
** CVE added: https://cve.org/CVERecord?id=CVE-2026-4775
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2153363
Title:
Merge tiff from Debian for stonking cycle
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/tiff/+bug/2153363/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs