Bug 511015 - CVE-2009-2285 libtiff: LZWDecodeCompat underflow
Summary: CVE-2009-2285 libtiff: LZWDecodeCompat underflow
Alias: None
Product: Fedora
Classification: Fedora
Component: mingw32-libtiff
Version: rawhide
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Michael Ploujnikov
QA Contact: Fedora Extras Quality Assurance
URL: http://fedoraproject.org/wiki/Securit...
Depends On:
Blocks: CVE-2009-2285
TreeView+ depends on / blocked
Reported: 2009-07-13 09:00 UTC by Tomas Hoger
Modified: 2009-07-19 10:24 UTC (History)
1 user (show)

Fixed In Version: 3.8.2-17.fc11
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2009-07-19 10:11:42 UTC

Attachments (Terms of Use)

Description Tomas Hoger 2009-07-13 09:00:19 UTC
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.

For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.

	bug #507465: CVE-2009-2285 libtiff: LZWDecodeCompat underflow

When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available and only close this bug once all affected Fedora versions are fixed.

Bodhi update submission link:

Comment 2 Fedora Update System 2009-07-13 23:18:29 UTC
mingw32-libtiff-3.8.2-17.fc10 has been submitted as an update for Fedora 10.

Comment 3 Fedora Update System 2009-07-13 23:45:52 UTC
mingw32-libtiff-3.8.2-17.fc11 has been submitted as an update for Fedora 11.

Comment 4 Fedora Update System 2009-07-19 10:11:38 UTC
mingw32-libtiff-3.8.2-17.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2009-07-19 10:24:25 UTC
mingw32-libtiff-3.8.2-17.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.