Re: CVE-2017-9935 / tiff

2017-12-11 Thread Brian May
Brian May writes: > I note that the previous version of tiff3 is a security update for > tiff2pdf. I also note that there seem to be a number of reverse depends of tiff3 in wheezy. Here is a version of tiff3 available for testing. https://people.debian.org/~bam/debian/pool/main/t/tiff3/ Unfor

Re: reportbug: please inform security and lts teams about security update regressions

2017-12-11 Thread Salvatore Bonaccorso
Hi Markus, On Sun, Dec 10, 2017 at 03:58:30PM +0100, Markus Koschany wrote: > Am 10.12.2017 um 13:35 schrieb Salvatore Bonaccorso: > [...] > >>> and beeing accessible under > >>> https://security-tracker.debian.org/tracker/distributions.json > >> > >> That makes as lot of sense! (I used YAML in t

Re: CVE-2017-9935 / tiff

2017-12-11 Thread Brian May
Brian May writes: > Now to see if the patch will apply to the older tiff3, also in wheezy. Done. I note that the previous version of tiff3 is a security update for tiff2pdf. However I also note that - for the tiff3 package - we don't build a binary for tiff2pdf. The newer tiff package is used