UbuntuUpdates.org

Package "tiff"

Name: tiff

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Tag Image File Format library (TIFF), development files
  • TIFF manipulation and conversion documentation
  • Tag Image File Format library (TIFF), development files (transitional package)
  • Tag Image File Format (TIFF) library

Latest version: 4.5.1+git230720-4ubuntu4.1
Release: plucky (25.04)
Level: security
Repository: main

Links



Other versions of "tiff" in Plucky

Repository Area Version
base main 4.5.1+git230720-4ubuntu4
base universe 4.5.1+git230720-4ubuntu4
security universe 4.5.1+git230720-4ubuntu4.1
updates main 4.5.1+git230720-4ubuntu4.1
updates universe 4.5.1+git230720-4ubuntu4.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 4.5.1+git230720-4ubuntu4.1 2025-08-20 18:27:12 UTC

  tiff (4.5.1+git230720-4ubuntu4.1) plucky-security; urgency=medium

  * SECURITY UPDATE: null-pointer dereference
    - d/p/CVE-2025-8534.patch: tiff2ps: check return of TIFFGetFiled() to
      fix
    - CVE-2025-8534
  * SECURITY UPDATE: use-after-free issue
    - d/p/CVE-2025-8176.patch: fix heap use-after-free in tiffmedian
    - CVE-2025-8176
  * SECURITY UPDATE: stack-based buffer overflow
    - d/p/CVE-2025-8851.patch: address tiffcrop buffer overflow issues
    - CVE-2025-8851

 -- Nishit Majithia <email address hidden> Wed, 20 Aug 2025 15:49:38 +0530

CVE-2025-8534 A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c
CVE-2025-8176 A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file
CVE-2025-8851 A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.



About   -   Send Feedback to @ubuntu_updates