-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 26 Jan 2017 13:27:21 +0000 Source: tiff3 Binary: libtiff4 libtiffxx0c2 libtiff4-dev Architecture: source amd64 Version: 3.9.6-11+deb7u3 Distribution: wheezy-security Urgency: low Maintainer: Jay Berkenbilt <qjb@debian.org> Changed-By: Raphaël Hertzog <hertzog@debian.org> Description: libtiff4 - Tag Image File Format (TIFF) library (old version) libtiff4-dev - Tag Image File Format (TIFF) library (old version), development f libtiffxx0c2 - Tag Image File Format (TIFF) library (old version) -- C++ interfa Closes: 852610 Changes: tiff3 (3.9.6-11+deb7u3) wheezy-security; urgency=low . * When writing out a TIFF file, skip codec-specific tags that are not relevant for the current codec (compression scheme). Closes: #852610 This fixes a regression introduced by CVE-2014-8128-5-fixed.patch and CVE-2016-5318_CVE-2015-7554.patch. Checksums-Sha1: 74aec5eaf4c2828270f376858faee10f49b8b8c9 1650 tiff3_3.9.6-11+deb7u3.dsc 541faea960e5015bfab116166ea6ce02f9a23543 41639 tiff3_3.9.6-11+deb7u3.debian.tar.gz 1fa6aac54a41c702a87104e16e6ae1451b098c81 204112 libtiff4_3.9.6-11+deb7u3_amd64.deb fb0222d54e4393ad3be2d3fba1129b2069664ebd 64280 libtiffxx0c2_3.9.6-11+deb7u3_amd64.deb 63c3d83d4affb83bf28df76b20716fdbeb14ea1d 338996 libtiff4-dev_3.9.6-11+deb7u3_amd64.deb Checksums-Sha256: dc8f0affa3c3711fb8e4a4f2f857abf40f23b78d608093638097d467dd688f8f 1650 tiff3_3.9.6-11+deb7u3.dsc a9013ca17f0de7ea8e63f1dd2529a5a100f365cffdf5258248ae52ae2c91884d 41639 tiff3_3.9.6-11+deb7u3.debian.tar.gz c84d9e922d536952af9bde2d4383a35d28471b7dd23b831777cb56481deeac0c 204112 libtiff4_3.9.6-11+deb7u3_amd64.deb f2583474d9c87e35f3362bb42778414d3e77381726a625239aefe91d56eac098 64280 libtiffxx0c2_3.9.6-11+deb7u3_amd64.deb 1cfa9a0d95f03103bc586c5e5d6f9ab2d72c8a9e7aa62dbc23cc4521f86daf2d 338996 libtiff4-dev_3.9.6-11+deb7u3_amd64.deb Files: a52d2da5f723d3ad2f92faafe81e03db 1650 oldlibs optional tiff3_3.9.6-11+deb7u3.dsc 3f25415920645fdc26f01c14e957c6bd 41639 oldlibs optional tiff3_3.9.6-11+deb7u3.debian.tar.gz 8b8839b6818aa99248364e27e57f1c12 204112 oldlibs optional libtiff4_3.9.6-11+deb7u3_amd64.deb 6631d94f3386f4698d22b4f9378b7d61 64280 oldlibs optional libtiffxx0c2_3.9.6-11+deb7u3_amd64.deb f55ae7d49ccd3e9d3b6e948762687ed6 338996 libdevel optional libtiff4-dev_3.9.6-11+deb7u3_amd64.deb -----BEGIN PGP SIGNATURE----- Comment: Signed by Raphael Hertzog iQEzBAEBCgAdFiEE1823g1EQnhJ1LsbSA4gdq+vCmrkFAliPQtIACgkQA4gdq+vC mrmZrwf8C2ONEAdkbFf4UgiVVOYbZ066tzLP9f2COwFP88aj6wFec3gTbqZa4XW+ BeCZLo0ZFL50oXVejGh0PWIM8nLadDQPm2LdCo9oVCliiXhEYY0nYJ8k01r7WFZK oPwFdnEWgOGDXhVNf+XpToq2TVP5SVZ30mD+qpqJIVDuXH0p3NKfNIT4mNWbFpnI papNibkfh0mSDH1jA0CQO/AkGXFCetVjiBgavbzAIXiFymSxqIN/CVUslJkhyqOY 4rngIRwp+NXpMICCvhFxC+t29oGqeSkaeDbtd3JtYzqssOCOLyjK8snGAZXp2msl qbh/uKP3145rfT4f+AAEtUpvhQqAGg== =n6Rz -----END PGP SIGNATURE-----