SECURITY: tiff

Yaakov (Cygwin/X) yselkowitz@users.sourceforge.net
Sun Apr 3 20:17:00 GMT 2011


Chuck,

Security vulnerabilities have been announced in the tiff package.  The
remedy is to update to the latest 3.9.4 release AND apply the following
patches:

http://pkgs.fedoraproject.org/gitweb/?p=libtiff.git;a=blob_plain;f=libtiff-CVE-2011-0192.patch
http://pkgs.fedoraproject.org/gitweb/?p=libtiff.git;a=blob_plain;f=libtiff-CVE-2011-1167.patch

Further information:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0192
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1167


Yaakov




More information about the Cygwin-apps mailing list