*** This bug has been split off bug 143577 *** ------- Original comment by Josh Bressers (Security Response Team) on 2004.12.22 10:33 ------- Dmitry V. Levin has reported to vendor-sec an issue with tiffdump. The issue appears to be an integer overflow which could lead to a buffer overflow. There is no patch yet. More work is being done on this issue. I'll post more information when it's available. This issue should also affect RHEL2.1
I have built libtiff-3.6.1-8 into dist-4E-errata-candidate containing the fix.
Lifting embargo
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2005-035.html