Accepting request 607515 from home:pgajdos

- security update
  * CVE-2018-10963 [bsc#1092949]
    + tiff-CVE-2018-10963.patch

OBS-URL: https://build.opensuse.org/request/show/607515
OBS-URL: https://build.opensuse.org/package/show/graphics/tiff?expand=0&rev=116
This commit is contained in:
Ismail Dönmez 2018-05-15 12:56:19 +00:00 committed by Git OBS Bridge
parent facb4b0d94
commit 276dcc784a
3 changed files with 28 additions and 0 deletions

19
tiff-CVE-2018-10963.patch Normal file
View File

@ -0,0 +1,19 @@
diff --git a/libtiff/tif_dirwrite.c b/libtiff/tif_dirwrite.c
index 2430de6..c15a28d 100644
--- a/libtiff/tif_dirwrite.c
+++ b/libtiff/tif_dirwrite.c
@@ -695,8 +695,11 @@ TIFFWriteDirectorySec(TIFF* tif, int isimage, int imagedone, uint64* pdiroff)
}
break;
default:
- assert(0); /* we should never get here */
- break;
+ TIFFErrorExt(tif->tif_clientdata,module,
+ "Cannot write tag %d (%s)",
+ TIFFFieldTag(o),
+ o->field_name ? o->field_name : "unknown");
+ goto bad;
}
}
}

View File

@ -1,3 +1,10 @@
-------------------------------------------------------------------
Tue May 15 12:26:45 UTC 2018 - pgajdos@suse.com
- security update
* CVE-2018-10963 [bsc#1092949]
+ tiff-CVE-2018-10963.patch
-------------------------------------------------------------------
Tue Feb 20 16:18:33 UTC 2018 - mvetter@suse.com

View File

@ -32,6 +32,7 @@ Patch1: tiff-4.0.3-compress-warning.patch
# Contained in upstream repo. See bsc#1046077 for commit IDs.
Patch2: tiff-4.0.9-bsc1046077-CVE-2017-9935.patch
Patch3: tiff-4.0.9-bsc1081690-CVE-2018-5784.patch
Patch4: tiff-CVE-2018-10963.patch
BuildRequires: gcc-c++
BuildRequires: libjpeg-devel
@ -97,6 +98,7 @@ the libtiff library.
%patch1 -p1
%patch2 -p1
%patch3 -p1
%patch4 -p1
%build
CFLAGS="%{optflags} -fPIE"