Re: tiff-3.9.4-4 fixes CVE-2010-3364

2010-10-03 Thread Adam D. Barratt
On Sat, 2010-10-02 at 13:44 -0400, Jay Berkenbilt wrote: > I had overlooked that bug 595064 was a security bug that fixed > CVE-2010-3364. I think perhaps a CVE number had not been assigned when > the bug was originally reported. In any case, I upgraded the bug to > grave and uploaded tiff-3.9.4-

tiff-3.9.4-4 fixes CVE-2010-3364

2010-10-02 Thread Jay Berkenbilt
I had overlooked that bug 595064 was a security bug that fixed CVE-2010-3364. I think perhaps a CVE number had not been assigned when the bug was originally reported. In any case, I upgraded the bug to grave and uploaded tiff-3.9.4-4 with a fix to it. The fix changes one line of code, and I did