Re: tiff / CVE-2018-15209

2018-08-31 Thread Antoine Beaupré
On 2018-08-29 12:24:30, Brian May wrote: > Antoine Beaupré writes: > >> Brian, are you sure you're getting those failures in jessie? Which >> architecture? Here my tests were done in a VirtualBox VM using an up to >> date Debian jessie amd64 box. > > My tests were done in a schroot. Not sure if I

Re: tiff / CVE-2018-15209

2018-08-28 Thread Brian May
Antoine Beaupré writes: > Brian, are you sure you're getting those failures in jessie? Which > architecture? Here my tests were done in a VirtualBox VM using an up to > date Debian jessie amd64 box. My tests were done in a schroot. Not sure if I used i386 or amd64 now. -- Brian May

Re: tiff / CVE-2018-15209

2018-08-27 Thread Antoine Beaupré
On 2018-08-14 17:27:29, Brian May wrote: > I have been trying to reproduce this bug (buffer overflow), but instead > I get increasing memory usage until my computer crashes. With versions > from Jessie, Stretch, and Sid. So maybe another security issue? > > I note that CVE-2017-11613 and CVE-2018-5

tiff / CVE-2018-15209

2018-08-14 Thread Brian May
I have been trying to reproduce this bug (buffer overflow), but instead I get increasing memory usage until my computer crashes. With versions from Jessie, Stretch, and Sid. So maybe another security issue? I note that CVE-2017-11613 and CVE-2018-5784 can use unbounded memory. However these are ma