1 Name: LibTIFF 2 URL: http://www.remotesensing.org/libtiff/ 3 Version: 4.0.6 4 Security Critical: yes 5 License: BSD 6 7 Description: 8 TIFF library. 9 10 Local Modifications: 11 12 0000-build-config.patch: Local build configuration changes. 13 0001-build-config.patch: Enable HAVE_SEARCH_H in tiffconf.h for VS 2015 14 0002-CVE-2015-8665-8683.patch: Security fixes 15 0003-CVE-2015-8781-8782-8783.patch: Security fixes 16 0004-CVE-2015-8784.patch: Security fixes 17 0005-Leak-TIFFFetchStripThing.patch: Fix a memory leak 18 0006-HeapBufferOverflow-ChopUpSingleUncompressedStrip.patch: Fix a heap buffer overflow 19 0007-uninitialized-value.patch: Fix potentially uninitialized dircount value 20 0008-HeapBufferOverflow-ChopUpSingleUncompressedStrip.patch: Fix a heap buffer overflow 21 0009-HeapBufferOverflow-PixarLogDecode.patch: Fix a heap buffer overflow 22 0010-fix-leak-imagebegin: Fix a leak when TIFFRGBAImageBegin fails 23 0011-fix-leak-imagebegin2: Apply upstream fix related to our previous patch 24 0012-initialize-tif-rawdata.patch: Initialize tif_rawdata to guard against unitialized access 25 0013-validate-refblackwhite.patch: Make sure the refblackwhite values aren't nan. 26 0014-cast-to-unsigned-in-putagreytile.patch: casting to avoid undefined shifts. 27 0015-fix-leaks-in-tif_ojpeg.patch: fix direct leaks in tif_ojpeg.c methods 28 0016-fix-leak-in-pixarlogsetupdecode.patch: Free sp->tbuf if setup fails 29 0017-safe_skews_in_gtTileContig.patch: return error if to/from skews overflow from int32. 30 0018-fix-leak-in-PredictorSetupDecode.patch: call tif->tif_cleanup if the setup fails. 31 0019-fix-invalid-reads-TIFFFetchNormalTag.patch: upstream security fix in tif_dirread. 32 0020-unreasonable-td-bitspersample.patch: upstream patch ignoring large td_bitspersample. 33 0021-fix-leaks-ojpegreaderinfosectables.patch: more direct leak fixes in tif_ojpeg.c. 34