~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
PublicDateAtUSN: 2016-06-15
Candidate: CVE-2016-5314
PublicDate: 2016-06-15
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5314
 http://seclists.org/oss-sec/2016/q2/543
 http://www.ubuntu.com/usn/usn-3212-1
Description:
 PixarLogDecode() out-of-bound writes
Ubuntu-Description:
Notes:
Bugs:
 http://bugzilla.maptools.org/show_bug.cgi?id=2554
 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=830700
Priority: medium
Discovered-by: Kaixiang Zhang
Assigned-to:

Patches_tiff:
 vendor: https://git.centos.org/blob/rpms!libtiff.git/1ad9335dc0c1325262c62842eda01476243ec821/SOURCES!libtiff-CVE-2016-5320.patch
 upstream: https://github.com/vadz/libtiff/commit/391e77fcd217e78b2c51342ac3ddb7100ecacdd2
upstream_tiff: released (4.0.7)
precise_tiff: ignored (reached end-of-life)
precise/esm_tiff: needed
trusty_tiff: released (4.0.3-7ubuntu0.6)
vivid/stable-phone-overlay_tiff: ignored (reached end-of-life)
vivid/ubuntu-core_tiff: DNE
wily_tiff: ignored (reached end-of-life)
xenial_tiff: released (4.0.6-1ubuntu0.1)
yakkety_tiff: not-affected (4.0.6-2)
zesty_tiff: not-affected (4.0.7-1)
devel_tiff: not-affected (4.0.7-1)