------------------------------------------------------------------- Fri Nov 14 06:17:01 UTC 2025 - GONG Jie - tiff-CVE-2025-8176.patch: CVE-2025-8176 [bsc#1253310] - tiff-CVE-2025-9900.patch: CVE-2025-9900 [bsc#1253310] ------------------------------------------------------------------- Mon Feb 27 17:18:00 UTC 2023 - Thomas Abraham - tiff-CVE-2022-3970.patch: CVE-2022-3970 [bsc#1205392 , bsc#1208338] ------------------------------------------------------------------- Thu Nov 10 15:08:12 UTC 2022 - Ales Novak - tiff-CVE-2022-34526.patch: CVE-2022-34526 [bsc#1202026, bsc#1205073] ------------------------------------------------------------------- Thu Nov 10 15:06:26 UTC 2022 - alnovak@suse.com - LEVEL 3 SUPPORT STARTS HERE - All changes above this marker are made by SUSE L3 Team. =================================================================== ------------------------------------------------------------------- Mon Jan 17 15:25:57 UTC 2022 - Michael Vetter - security update: Fix OOB in tif_getimage.c * CVE-2015-8665[bsc#1156749] CVE-2015-8683[bsc#1156754] + tiff-CVE-2015-8665,CVE-2015-8683.patch - security update: Fix memory allocation failure in tif_read.c * CVE-2020-35521[bsc#1182808] CVE-2020-35522[bsc#1182809] + tiff-CVE-2020-35521,CVE-2020-35522.patch - security update: Fix heap-based buffer overflow in TIFF2PDF tool * CVE-2020-35524[bsc#1182812] + tiff-CVE-2020-35524.patch - security update: Fix integer overflow in tif_getimage * CVE-2020-35523 [bsc#1182811] + tiff-CVE-2020-35523.patch ------------------------------------------------------------------- Tue Feb 12 18:54:21 UTC 2019 - Petr Gajdos - security update * CVE-2016-5102 [bsc#983268] + tiff-CVE-2016-5102.patch ------------------------------------------------------------------- Mon Feb 4 14:31:36 UTC 2019 - mvetter@suse.com - security update * CVE-2019-6128 [bsc#1121626] + tiff-CVE-2019-6128.patch ------------------------------------------------------------------- Wed Nov 21 14:48:11 UTC 2018 - Petr Gajdos - security update: * CVE-2016-10092, CVE-2016-10093, CVE-2016-10094 [bsc#1017693] + tiff-CVE-2016-10092,10093,10094.patch plus previous patches ------------------------------------------------------------------- Mon Nov 12 14:03:46 UTC 2018 - Petr Gajdos - security update * CVE-2018-18661 [bsc#1113672] + tiff-CVE-2018-18661.patch * CVE-2018-12900 [bsc#1099257] + tiff-CVE-2018-12900.patch * CVE-2016-9273 [bsc#1010163] + tiff-CVE-2016-9273.patch * CVE-2017-9147 [bsc#1040322] . tiff-CVE-2014-8128,CVE-2015-7554,CVE-2016-5318,10095,8331,3632.patch renamed to tiff-CVE-2014-8128,CVE-2015-7554,CVE-2016-5318,10095,8331,3632,CVE-2017-9147.patch - debug_build: build more suitable for debugging ------------------------------------------------------------------- Wed Oct 17 11:32:08 UTC 2018 - Petr Gajdos - security update * CVE-2018-17100 [bsc#1108637] + tiff-CVE-2018-17100.patch * CVE-2018-17101 [bsc#1108627] + tiff-CVE-2018-17101.patch * CVE-2018-17795 [bsc#1110358] % tiff-CVE-2017-9935,17973.patch renamed to tiff-CVE-2017-9935,17973,CVE-2018-17795.patch * CVE-2018-16335 [bsc#1106853] % tiff-CVE-2017-11613.patch renamed to tiff-CVE-2017-11613,CVE-2018-16335.patch ------------------------------------------------------------------- Mon Aug 27 13:02:33 UTC 2018 - pgajdos@suse.com - security update * CVE-2017-17942 [bsc#1074186], CVE-2016-5319 [bsc#983440], CVE-2016-3619 [bsc#974446], CVE-2016-3620 [bsc#974447] CVE-2016-3621 [bsc#974448], CVE-2017-9117 [bsc#1040080] + tiff-bmp2tiff.c-update.patch ------------------------------------------------------------------- Wed Aug 15 15:12:42 UTC 2018 - pgajdos@suse.com - security update * CVE-2018-10779 [bsc#1092480] + tiff-CVE-2018-10779.patch ------------------------------------------------------------------- Tue Jul 31 10:55:46 UTC 2018 - mvetter@suse.com - security update * CVE-2015-8668 [bsc#960589] + tiff-CVE-2015-8668.patch ------------------------------------------------------------------- Mon Jun 4 09:36:30 UTC 2018 - pgajdos@suse.com - security update * CVE-2017-5225 [bsc#1019611] + tiff-CVE-2017-5225.patch * CVE-2018-7456 [bsc#1082825] + tiff-CVE-2018-7456.patch * CVE-2017-11613 [bsc#1082332] + tiff-CVE-2017-11613.patch * CVE-2016-9540 [bsc#1011839] + tiff-CVE-2016-9540.patch * CVE-2016-9535 [bsc#1011846] + tiff-CVE-2016-9535.patch * CVE-2016-9535 [bsc#1011846] + tiff-CVE-2016-9535.patch * CVE-2016-10266 [bsc#1031263] + tiff-CVE-2016-10266.patch * CVE-2018-8905 [bsc#1086408] + tiff-CVE-2018-8905.patch ------------------------------------------------------------------- Mon May 14 09:19:47 UTC 2018 - pgajdos@suse.com - security update * multiple divide by zero issues incl. CVE-2016-10267 [bsc#1017694] + tiff-multiple-divide-by-zero.patch * CVE-2016-10270 [bsc#1031250] + tiff-CVE-2016-10270.patch * CVE-2017-7602 [bsc#1033109] + tiff-CVE-2017-7602.patch * CVE-2017-7596 [bsc#1033126] CVE-2017-7597 [bsc#1033120] CVE-2017-7599 [bsc#1033113] CVE-2017-7600 [bsc#1033112] * assert in readSeparateTilesIntoBuffer() function [bsc#1017689] + tiff-assert-readSeparateTilesIntoBuffer.patch * CVE-2017-7593 [bsc#1033129] + tiff-CVE-2017-7593.patch * CVE-2017-7595 [bsc#1033127] and CVE-2017-7601 [bsc#1033111] + tiff-CVE-2017-7595,7601.patch * CVE-2016-10269 [bsc#1031254] + tiff-CVE-2016-10269.patch * CVE-2017-18013 [bsc#1074317] + tiff-CVE-2017-18013.patch ------------------------------------------------------------------- Fri Apr 27 06:47:05 UTC 2018 - pgajdos@suse.com - security update * CVE-2016-9453 [bsc#1011107] * CVE-2016-5652 [bsc#1007280] * overlap of memcpy parameters [bsc#1017691] * invalid memory read [bsc#1017692] * CVE-2017-11335 [bsc#1048937] * CVE-2016-9536 [bsc#1011845] + tiff-tiff2pdf.c-update.patch * CVE-2017-9935 [bsc#1046077], CVE-2017-17973 [bsc#1074318] + tiff-CVE-2017-9935,17973.patch ------------------------------------------------------------------- Wed Apr 25 14:58:53 UTC 2018 - pgajdos@suse.com - security update * CVE-2015-7554 [bsc#960341], CVE-2014-8128 [bsc#960341], CVE-2016-5318 [bsc#983436], CVE-2016-10095 [bsc#1017690], CVE-2016-8331 [bsc#1007276], CVE-2016-3632 [bsc#974621] . modified tiff-3.8.2-CVE-2015-7554.patch and renamed to tiff-CVE-2014-8128,CVE-2015-7554,CVE-2016-5318,10095,8331,3632.patch + tiff-thumbnail-invalid-read.patch ------------------------------------------------------------------- Wed Apr 25 14:21:41 UTC 2018 - pgajdos@suse.com - security update * CVE-2016-10268 [bsc#1031255] + tiff-CVE-2016-10268.patch ------------------------------------------------------------------- Wed Apr 25 13:11:03 UTC 2018 - pgajdos@suse.com - refreshed patches using quilt * tiff-3.8.2-CVE-2016-3945.patch * tiff-3.8.2-libtiff-tif_pixarlog.c-fix-potential-buffer-write-ov.patch ------------------------------------------------------------------- Wed Feb 7 13:37:31 UTC 2018 - mvetter@suse.com - Add tiff-3.8.2-bsc1017688-nullptr_tiffinfo.patch: Fix bsc#1017688: NULL pointer dereference in TIFFReadRawData (tiffinfo.c) ------------------------------------------------------------------- Thu Oct 6 07:47:19 UTC 2016 - fstrba@suse.com - Added patches: * tiff-3.8.2-fix-various-out-of-bounds-write-vul.patch - Upstream fixes for MSVR 35094, MSVR 35095, MSVR 35098. * tiff-3.8.2-libtiff-tif_getimage.c-TIFFRGBAImageOK-Reject-attemp.patch - Enforce bits-per-sample requirements of floating point predictor. Fixes CVE-2016-3622 [bsc#974449] ------------------------------------------------------------------- Wed Oct 5 14:59:39 UTC 2016 - fstrba@suse.com - Added patches: * tiff-3.8.2-libtiff-tif_luv.c-validate-that-for-COMPRESSION_SGIL.patch * tiff-3.8.2-libtiff-tif_pixarlog.c-fix-potential-buffer-write-ov.patch - Upstream commits to fix CVE-2016-5314 [bsc#984831], CVE-2016-5316 [bsc#984837], CVE-2016-5317 [bsc#984842], CVE-2016-5320 [bsc#984808], CVE-2016-5315 [bsc#984809] and CVE-2016-5875 [bsc#987351] * tiff-3.8.2-CVE-2016-3623.patch * tiff-3.8.2-CVE-2016-3945.patch * tiff-3.8.2-CVE-2016-3990.patch - Upstream commits to fix CVE-2016-3623 [bsc#974618], CVE-2016-3945 [bsc#974614], CVE-2016-3990 [bsc#975069] ------------------------------------------------------------------- Wed Apr 6 13:56:19 UTC 2016 - fstrba@suse.com - Added patch: * tiff-3.8.2-CVE-2016-3186.patch - fix CVE-2016-3186: buffer overflow in gif2tiff [bsc#973340] ------------------------------------------------------------------- Mon Feb 1 08:01:19 UTC 2016 - fstrba@suse.com - Added patch: * tiff-3.8.2-CVE-2015-8782.patch - fix CVE-2015-8781, CVE-2015-8782, CVE-2015-8783: Out-of-bounds writes for invalid images (upstream bug #2522) [bsc#964225] ------------------------------------------------------------------- Fri Jan 15 15:35:25 UTC 2016 - fstrba@suse.com - Added patch: * tiff-3.8.2-CVE-2015-7554.patch - fix CVE-2015-7554: Out-of-bounds Write in the thumbnail and tiffcmp tools (upsteam bug #2499) [bsc#960341] ------------------------------------------------------------------- Mon Feb 16 08:14:26 UTC 2015 - pgajdos@suse.com - security update: CVE-2014-9655, CVE-2014-8127, CVE-2014-8128, CVE-2014-8129, CVE-2014-8130, CVE-2015-1547 bnc#914890, bnc#916925, bnc#916927 CVE-2015-8870 bsc#1014461 + erouault.2856.patch + erouault.2857.patch + erouault.2858.patch + erouault.2859.patch + erouault.2860.patch + erouault.2861.patch + erouault.2862.patch + erouault.2863.patch + erouault.2876.patch + bfriesen.2805.patch + tiff-dither-malloc-check.patch ------------------------------------------------------------------- Wed Aug 21 13:08:34 UTC 2013 - pgajdos@suse.com - security update * CVE-2013-4232.patch [bnc#834477] * CVE-2013-4231.patch [bnc#834477] * CVE-2013-4244.patch [bnc#834788] * CVE-2013-4243.patch [bnc#834779] - refreshed bnc788741-mem-crash.patch using quilt ------------------------------------------------------------------- Thu May 2 12:34:52 UTC 2013 - pgajdos@suse.com - security update * CVE-2013-1961.patch [bnc#818117] * CVE-2013-1960.patch [bnc#817573] ------------------------------------------------------------------- Mon Nov 12 08:28:02 UTC 2012 - pgajdos@suse.com - fixed: * heap-based memory corruption [bnc#788741] + bnc788741-mem-crash.patch * CVE-2012-4447 [bnc#781995] * CVE-2012-4564 [bnc#787892] * CVE-2012-5581 [bnc#791607] ------------------------------------------------------------------- Thu Jul 12 13:58:58 UTC 2012 - pgajdos@suse.com - fixed CVE-2012-3401 [bnc#770816] ------------------------------------------------------------------- Wed Jun 20 13:52:09 UTC 2012 - pgajdos@suse.com - fixed * CVE-2012-2113 [bnc#767852] * CVE-2012-2088 [bnc#767854] ------------------------------------------------------------------- Mon Apr 2 12:49:26 UTC 2012 - pgajdos@suse.com - fixed CVE-2012-1173 [bnc#753362] ------------------------------------------------------------------- Thu Apr 14 16:52:54 CEST 2011 - pgajdos@suse.cz - fixed integer overflow CVE-2010-4665 [bnc#687442] ------------------------------------------------------------------- Thu Mar 31 12:46:11 CEST 2011 - pgajdos@suse.cz - fixed regression caused by previous update [bnc#682871] * modified CVE-2011-0192.patch - fixed tiff2pdf output [bnc#599475] * tiff2pdf-colors.patch - fixed buffer overflow in thunder decoder [bnc#683337] * added CVE-2011-1167.patch ------------------------------------------------------------------- Thu Feb 17 16:34:12 CET 2011 - pgajdos@suse.cz - fixed buffer overflows [bnc#672510] * CVE-2011-0192.patch * CVE-2011-0191.patch ------------------------------------------------------------------- Thu May 20 14:59:00 CEST 2010 - pgajdos@suse.cz - fixed integer overflows [bnc#605837] * CVE-2010-1411.patch ------------------------------------------------------------------- Thu Aug 6 15:29:56 CEST 2009 - pgajdos@suse.cz - fixed integer overflows [bnc#519796] * CVE-2009-2347.patch ------------------------------------------------------------------- Thu Jul 2 16:39:44 CEST 2009 - nadvornik@suse.cz - fixed lzw overflow CVE-2009-2285 [bnc#518698] ------------------------------------------------------------------- Wed Feb 4 15:51:58 CET 2009 - nadvornik@suse.cz - fixed an endless loop on invalid images (bnc#444079) CVE-2008-1586 ------------------------------------------------------------------- Tue Jan 13 16:19:37 CET 2009 - olh@suse.de - obsolete old libtiff-64bit on ppc64 (bnc#437293) ------------------------------------------------------------------- Wed Jan 7 12:34:56 CET 2009 - olh@suse.de - obsolete old -XXbit packages (bnc#437293) ------------------------------------------------------------------- Sun Sep 7 11:24:56 CEST 2008 - schwab@suse.de - Fix conflicting options. ------------------------------------------------------------------- Tue Aug 19 17:45:10 CEST 2008 - nadvornik@suse.cz - fixed buffer overflows in LZW code (CVE-2008-2327) [bnc#414946] ------------------------------------------------------------------- Sun May 18 10:37:18 CEST 2008 - coolo@suse.de - fix rename of xxbit packages ------------------------------------------------------------------- Thu Apr 10 12:54:45 CEST 2008 - ro@suse.de - added baselibs.conf file to build xxbit packages for multilib support ------------------------------------------------------------------- Fri Jul 27 15:58:49 CEST 2007 - ro@suse.de - add provides and obsoletes for libtiff to libtiff3 package ------------------------------------------------------------------- Thu Jul 19 15:01:40 CEST 2007 - nadvornik@suse.cz - renamed libtiff to libtiff3 - do not package static libraries - added zlib-devel to BuildRequires ------------------------------------------------------------------- Mon Jun 12 13:40:43 CEST 2006 - nadvornik@suse.cz - fixed a typo in the previous change [#179051] ------------------------------------------------------------------- Fri Jun 2 17:17:55 CEST 2006 - nadvornik@suse.cz - fixed buffer overflow in tiffsplit (CVE-2006-2656) [#179051] - fixed buffer overflow in tiff2pdf [#179587] ------------------------------------------------------------------- Wed Apr 12 11:01:27 CEST 2006 - nadvornik@suse.cz - updated to 3.8.2 [#165237] * bugfix release * fixed several segfaults caused by incorrect tiff data ------------------------------------------------------------------- Tue Feb 7 15:09:45 CET 2006 - nadvornik@suse.cz - fixed crash on certain tiff images CVE-2006-0405 [#145757] ------------------------------------------------------------------- Wed Jan 25 21:31:02 CET 2006 - mls@suse.de - converted neededforbuild to BuildRequires ------------------------------------------------------------------- Thu Jan 12 16:32:23 CET 2006 - nadvornik@suse.cz - compile with -fstack-protector ------------------------------------------------------------------- Tue Jan 3 15:01:35 CET 2006 - nadvornik@suse.cz - updated to 3.8.0: * Read-only support for custom directories (e.g. EXIF directory) * Preliminary support for MS MDI format ------------------------------------------------------------------- Mon Oct 10 15:13:48 CEST 2005 - nadvornik@suse.cz - built with -fno-strict-aliasing ------------------------------------------------------------------- Fri Jul 15 15:35:41 CEST 2005 - nadvornik@suse.cz - updated to 3.7.3 ------------------------------------------------------------------- Tue May 24 17:13:51 CEST 2005 - nadvornik@suse.cz - updated to 3.7.2 - fixed 64bit bug in ppm2tiff [#85440] - fixed buffer overflow in BitsPerSample [#82787] ------------------------------------------------------------------- Thu Feb 17 13:38:57 CET 2005 - nadvornik@suse.cz - fixed reading of alpha channel ------------------------------------------------------------------- Sun Jan 16 20:05:53 CET 2005 - ro@suse.de - added c++ to neededforbuild ------------------------------------------------------------------- Fri Jan 7 15:41:40 CET 2005 - nadvornik@suse.cz - use typedef int int32 on all architectures ------------------------------------------------------------------- Wed Jan 05 15:42:09 CET 2005 - nadvornik@suse.cz - disabled c++ API as it would add a dependency on c++ libraries ------------------------------------------------------------------- Mon Jan 03 17:50:47 CET 2005 - nadvornik@suse.cz - updated to 3.7.1: bugfix release ------------------------------------------------------------------- Wed Dec 15 21:04:47 CET 2004 - nadvornik@suse.cz - added README.SUSE pointing to the documentation [#48601] - moved man3 to devel subpackage ------------------------------------------------------------------- Fri Oct 22 18:38:53 CEST 2004 - nadvornik@suse.cz - updated to 3.7.0 - security fixes are included in mainstream ------------------------------------------------------------------- Wed Oct 20 09:59:41 CEST 2004 - meissner@suse.de - Initialize ycbcrsubsampling to be not 0 in case of bad tiffs to avoid denial of service by divison/0. ------------------------------------------------------------------- Tue Oct 12 15:20:16 CEST 2004 - nadvornik@suse.cz - do not call TIFFTileSize with uninitialized values [#44635] ------------------------------------------------------------------- Thu Oct 07 18:44:29 CEST 2004 - pmladek@suse.cz - fixed much more buffer overflows (the older tiff-alt-bound-CheckMalloc.patch is included in the new libtiff-3.6.1-alt-bound.patch now) [#44635] ------------------------------------------------------------------- Thu Sep 30 18:33:05 CEST 2004 - nadvornik@suse.cz - fixed more buffer overflows [#44635] ------------------------------------------------------------------- Tue Sep 21 17:47:00 CEST 2004 - nadvornik@suse.cz - fixed multiple buffer overflows - CAN-2004-0803 [#44635] - disabled old jpeg support because of security problems [#45116] ------------------------------------------------------------------- Tue Aug 31 16:23:04 CEST 2004 - nadvornik@suse.cz - added LZW support ------------------------------------------------------------------- Wed Aug 25 13:39:39 CEST 2004 - kukuk@suse.de - Create -devel subpackage - Add libjpeg-devel to neededforbuild - Avoid /bin/sh in PreRequires ------------------------------------------------------------------- Fri Jul 2 16:10:10 CEST 2004 - max@suse.de - port.h is needed as well. ------------------------------------------------------------------- Thu May 6 17:08:54 CEST 2004 - max@suse.de - Install private headers (tif_dir.h, tiffiop.h). ------------------------------------------------------------------- Tue Apr 27 16:42:03 CEST 2004 - nadvornik@suse.cz - fixed tif_fax3 from cvs [#39515] ------------------------------------------------------------------- Mon Feb 09 12:27:05 CET 2004 - nadvornik@suse.cz - updated to 3.6.1 - fixed dangerous compiler warnings ------------------------------------------------------------------- Sat Jan 10 20:14:17 CET 2004 - adrian@suse.de - add %defattr and %run_ldconfig ------------------------------------------------------------------- Wed May 21 01:06:35 CEST 2003 - ro@suse.de - remove cvs subdirs ------------------------------------------------------------------- Sat Jul 27 14:15:49 CEST 2002 - kukuk@suse.de - Provide libtiff-devel in libtiff [Bug #17260] ------------------------------------------------------------------- Fri Jul 26 21:37:50 CEST 2002 - adrian@suse.de - fix neededforbuild ------------------------------------------------------------------- Wed Jul 3 13:41:23 CEST 2002 - nadvornik@suse.cz - fixed segfault in fax2tiff [bug #16818] - fixed size of int32 on 64bit architectures ------------------------------------------------------------------- Wed Jun 26 01:25:38 CEST 2002 - ro@suse.de - fixed directory permissions ------------------------------------------------------------------- Wed Jun 19 12:35:20 CEST 2002 - nadvornik@suse.cz - compiled with OJPEG_SUPPORT [bug #16408] ------------------------------------------------------------------- Thu Apr 18 23:05:34 CEST 2002 - kukuk@suse.de - Fix to compile on lib64 architectures ------------------------------------------------------------------- Wed Feb 6 14:48:39 CET 2002 - coolo@suse.de - use %_libdir ------------------------------------------------------------------- Thu Jan 24 11:53:02 CET 2002 - okir@suse.de - Fixed a tempfile race in fax2ps ------------------------------------------------------------------- Tue Dec 11 12:24:47 CET 2001 - nadvornik@suse.cz - updated to 3.5.7: bugfix release ------------------------------------------------------------------- Wed May 9 22:09:18 CEST 2001 - mfabian@suse.de - bzip2 sources ------------------------------------------------------------------- Thu Mar 15 19:11:58 CET 2001 - schwab@suse.de - Fix for ia64. ------------------------------------------------------------------- Fri May 26 16:16:59 CEST 2000 - bubnikv@suse.cz - sorted ------------------------------------------------------------------- Thu May 25 10:55:25 CEST 2000 - schwab@suse.de - Fix dso configure check for ia64. ------------------------------------------------------------------- Thu May 11 09:41:12 CEST 2000 - nadvornik@suse.cz - update to 3.5.5 - added BuildRoot ------------------------------------------------------------------- Tue Jan 25 17:12:06 CET 2000 - ro@suse.de - manpages to /usr/share using macro ------------------------------------------------------------------- Mon Jan 3 15:10:55 CET 2000 - schwab@suse.de - Update to 3.5.4 (Y2K fix) ------------------------------------------------------------------- Mon Sep 13 17:23:57 CEST 1999 - bs@suse.de - ran old prepare_spec on spec file to switch to new prepare_spec. ------------------------------------------------------------------- Wed Jan 13 18:07:04 MET 1999 - ro@suse.de - respect systems where libc is libc.so.6.1 (alpha) ------------------------------------------------------------------- Wed Nov 25 17:56:05 MET 1998 - ro@suse.de - update to 3.4 (final) named 3.4.final for rpm - moved from /usr/X11R6 to /usr ------------------------------------------------------------------- Wed Jul 29 19:01:00 MEST 1998 - werner@suse.de - Link shared libs explicit with -lc ------------------------------------------------------------------- Tue May 12 18:22:27 MEST 1998 - ro@suse.de - extracted package from libgr / build from own sources