Merge tiff 4.5.0-6 (main) from Debian unstable (main)

Bug #2020707 reported by Amin Bandali
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tiff (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Please merge tiff 4.5.0-6 (main) from Debian unstable (main)

Changelog entries since current mantic version 4.5.0-5ubuntu1:

tiff (4.5.0-6) unstable; urgency=high

  * Backport security fix for CVE-2023-2731, NULL pointer dereference flaw in
    LZWDecode() (closes: #1036282).

 -- Laszlo Boszormenyi (GCS) <email address hidden> Thu, 18 May 2023 18:20:39 +0200

Remaining changes:
    - Don't build with LERC on i386 because it requires numpy
      (Closes: #1017958)

Tags: patch

CVE References

Revision history for this message
Amin Bandali (bandali) wrote :
Jeremy Bícha (jbicha)
Changed in tiff (Ubuntu):
status: New → Fix Committed
information type: Public → Public Security
Revision history for this message
Ubuntu Foundations Team Bug Bot (crichton) wrote :

The attachment "debdiff to 4.5.0-6 in unstable" seems to be a debdiff. The ubuntu-sponsors team has been subscribed to the bug report so that they can review and hopefully sponsor the debdiff. If the attachment isn't a patch, please remove the "patch" flag from the attachment, remove the "patch" tag, and if you are member of the ~ubuntu-sponsors, unsubscribe the team.

[This is an automated message performed by a Launchpad user owned by ~brian-murray, for any issue please contact him.]

tags: added: patch
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package tiff - 4.5.0-6ubuntu1

---------------
tiff (4.5.0-6ubuntu1) mantic; urgency=medium

  * Merge from Debian unstable (LP: #2020707). Remaining changes:
    - Don't build with LERC on i386 because it requires numpy
      (Closes: #1017958)

tiff (4.5.0-6) unstable; urgency=high

  * Backport security fix for CVE-2023-2731, NULL pointer dereference flaw in
    LZWDecode() (closes: #1036282).

 -- Amin Bandali <email address hidden> Wed, 24 May 2023 16:13:57 -0400

Changed in tiff (Ubuntu):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.