Bug#280373: kfax libtiff vulnerabilities

2004-11-09 Thread Josh Metzler
On Monday 08 November 2004 10:13 pm, Chris Cheney wrote: > On Mon, Nov 08, 2004 at 09:35:30PM -0500, Josh Metzler wrote: > > On Monday 08 November 2004 07:46 pm, Chris Cheney wrote: > > > On Tue, Nov 09, 2004 at 12:37:55AM +0100, Andreas Mueller wrote: > > > > Package: kfax > > > > Version: 4:3.3.1

Bug#280373: kfax libtiff vulnerabilities

2004-11-08 Thread Ben Burton
> Did you happen to look at the source after > debian/patches/01_kdegraphics_branch.diff.uu is applied? The orig.tar.gz > is not patched directly of course... An understandable mistake. With many (most, I suspect) packages, the debian diffs are applied upon dpkg-source -x. For the KDE modules t

Bug#280373: kfax libtiff vulnerabilities

2004-11-08 Thread Adeodato Simó
* Chris Cheney [Mon, 08 Nov 2004 21:13:02 -0600]: > > It is not fixed in kdegraphics 3.3.1-1. I just downloaded the source > > (apt-get source kdegraphics), and the kfax.cpp is the version dated July > > 12, 2004 which is in the tagged KDE_3_3_1_RELEASE. The fix was committed > > to both KDE_

Bug#280373: kfax libtiff vulnerabilities

2004-11-08 Thread Chris Cheney
On Mon, Nov 08, 2004 at 09:35:30PM -0500, Josh Metzler wrote: > On Monday 08 November 2004 07:46 pm, Chris Cheney wrote: > > On Tue, Nov 09, 2004 at 12:37:55AM +0100, Andreas Mueller wrote: > > > Package: kfax > > > Version: 4:3.3.1-1 > > > Severity: normal > > > > > > > > > -- cut from the inoffic

Bug#280373: kfax libtiff vulnerabilities

2004-11-08 Thread Josh Metzler
On Monday 08 November 2004 07:46 pm, Chris Cheney wrote: > On Tue, Nov 09, 2004 at 12:37:55AM +0100, Andreas Mueller wrote: > > Package: kfax > > Version: 4:3.3.1-1 > > Severity: normal > > > > > > -- cut from the inoffical KDE Security Advisory -- > > > > kfax, a small utility for displaying fax f

Bug#280373: kfax libtiff vulnerabilities

2004-11-08 Thread Chris Cheney
On Tue, Nov 09, 2004 at 12:37:55AM +0100, Andreas Mueller wrote: > Package: kfax > Version: 4:3.3.1-1 > Severity: normal > > > -- cut from the inoffical KDE Security Advisory -- > > kfax, a small utility for displaying fax files, contains > for historic reasons a private copy of libtiff. > There

Bug#280373: kfax libtiff vulnerabilities

2004-11-08 Thread Andreas Mueller
Package: kfax Version: 4:3.3.1-1 Severity: normal -- cut from the inoffical KDE Security Advisory -- kfax, a small utility for displaying fax files, contains for historic reasons a private copy of libtiff. Therefore it is vulnerable to these issues as well. As a workaround, you can remove the k