From owner-freebsd-ports-bugs@FreeBSD.ORG Wed Jun 16 06:10:05 2010 Return-Path: Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 3B7111065672 for ; Wed, 16 Jun 2010 06:10:05 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 149408FC0C for ; Wed, 16 Jun 2010 06:10:05 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.4/8.14.4) with ESMTP id o5G6A3lu037467 for ; Wed, 16 Jun 2010 06:10:03 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.4/8.14.4/Submit) id o5G6A3ul037466; Wed, 16 Jun 2010 06:10:03 GMT (envelope-from gnats) Resent-Date: Wed, 16 Jun 2010 06:10:03 GMT Resent-Message-Id: <201006160610.o5G6A3ul037466@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-ports-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, dirk.meyer@dinoex.sub.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 837331065674 for ; Wed, 16 Jun 2010 06:04:47 +0000 (UTC) (envelope-from dm@home3.dinoex.sub.de) Received: from uucp.dinoex.sub.de (uucp.dinoex.sub.de [194.45.71.2]) by mx1.freebsd.org (Postfix) with ESMTP id E0C238FC08 for ; Wed, 16 Jun 2010 06:04:46 +0000 (UTC) Received: from home3.dinoex.sub.de (home3.dinoex.sub.de [194.45.71.20]) by uucp.dinoex.sub.de (8.14.4/8.14.2) with ESMTP id o5G64Odm072975 for ; Wed, 16 Jun 2010 08:04:40 +0200 (CEST) (envelope-from dm@home3.dinoex.sub.de) Received: (from dm@localhost) by home3.dinoex.sub.de (8.14.4/8.14.4/Submit) id o5G64PU7036520; Wed, 16 Jun 2010 08:04:25 +0200 (CEST) (envelope-from dm) Message-Id: <201006160604.o5G64PU7036520@home3.dinoex.sub.de> Date: Wed, 16 Jun 2010 08:04:25 +0200 (CEST) From: dirk.meyer@dinoex.sub.org To: FreeBSD-gnats-submit@FreeBSD.org X-Send-Pr-Version: 3.113 Cc: Subject: ports/147900: grahics/tiff Fix Integer overflows X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: dirk.meyer@dinoex.sub.org List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 16 Jun 2010 06:10:05 -0000 >Number: 147900 >Category: ports >Synopsis: grahics/tiff Fix Integer overflows >Confidential: no >Severity: non-critical >Priority: low >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: maintainer-update >Submitter-Id: current-users >Arrival-Date: Wed Jun 16 06:10:03 UTC 2010 >Closed-Date: >Last-Modified: >Originator: Dirk Meyer >Release: FreeBSD 8.1-PRERELEASE >Organization: privat >Environment: >Description: Fixes for CVE-2009-2347 in tiff2rgba Integer overflows in various inter-color space conversion tools http://www.remotesensing.org/libtiff/v3.9.4.html The code of the shared lib is not affected. Therefor the Fix is not urgent. >How-To-Repeat: Update needs appoval from portmrg@ >Fix: Impact: dependend packages will need a rfebuild, to have the new version number recorden in dependency. Please approve the patch below. Index: Makefile =================================================================== RCS file: /home/pcvs/ports/graphics/tiff/Makefile,v retrieving revision 1.75 diff -u -r1.75 Makefile --- Makefile 12 Jun 2010 16:45:42 -0000 1.75 +++ Makefile 16 Jun 2010 06:00:05 -0000 @@ -8,7 +8,7 @@ # PORTNAME= tiff -PORTVERSION= 3.9.3 +PORTVERSION= 3.9.4 CATEGORIES= graphics MASTER_SITES= ftp://ftp.remotesensing.org/pub/libtiff/ \ http://dl1.maptools.org/dl/libtiff/ Index: distinfo =================================================================== RCS file: /home/pcvs/ports/graphics/tiff/distinfo,v retrieving revision 1.28 diff -u -r1.28 distinfo --- distinfo 12 Jun 2010 16:45:42 -0000 1.28 +++ distinfo 16 Jun 2010 06:00:05 -0000 @@ -1,3 +1,3 @@ -MD5 (tiff-3.9.3.tar.gz) = 8e9c2ee955ed7d277dca83a972f306be -SHA256 (tiff-3.9.3.tar.gz) = 60e08794966b7cbf46bbf13c347f1fe41c982f98714909f49d6f198add4fdee6 -SIZE (tiff-3.9.3.tar.gz) = 1439203 +MD5 (tiff-3.9.4.tar.gz) = 2006c1bdd12644dbf02956955175afd6 +SHA256 (tiff-3.9.4.tar.gz) = 67b76d075fb74f7cb32e7e4b217701674755fe6cee0f463b259a753fce691da6 +SIZE (tiff-3.9.4.tar.gz) = 1436968 >Release-Note: >Audit-Trail: >Unformatted: