Re: A security bug in Debian Squeeze libtiff (+ non-updated ia32-libs??)

2012-04-07 Thread Mikulas Patocka
On Sat, 7 Apr 2012, Mikulas Patocka wrote: > > > On Sat, 7 Apr 2012, Mikulas Patocka wrote: > > > Hi > > > > There is a security bug in Debian Squeeze libtiff 3.9.4-5+sq. > > > > When loading corrupted images and with ElectricFence memory debugging > > enabled, programs using libtiff crash

Re: A security bug in Debian Squeeze libtiff (+ non-updated ia32-libs??)

2012-04-07 Thread Mikulas Patocka
On Sat, 7 Apr 2012, Mikulas Patocka wrote: > Hi > > There is a security bug in Debian Squeeze libtiff 3.9.4-5+sq. > > When loading corrupted images and with ElectricFence memory debugging > enabled, programs using libtiff crash. > > How to reproduce: Download corrupted images from here: > h

Re: A security bug in Debian Squeeze libtiff (+ non-updated ia32-libs??)

2012-04-07 Thread Moritz Mühlenhoff
Mikulas Patocka schrieb: > Hi > > There is a security bug in Debian Squeeze libtiff 3.9.4-5+sq. > > When loading corrupted images and with ElectricFence memory debugging > enabled, programs using libtiff crash. > > How to reproduce: Download corrupted images from here: > http://artax.karlin.mff.

Re: [Pkg-ia32-libs-maintainers] A security bug in Debian Squeeze libtiff (+ non-updated ia32-libs??)

2012-04-07 Thread Mikulas Patocka
On Sat, 7 Apr 2012, Thijs Kinkhorst wrote: > Hi, > > On Sat, April 7, 2012 06:24, Mikulas Patocka wrote: > > There is a security bug in Debian Squeeze libtiff 3.9.4-5+sq. > > Thanks for reporting. Just to clarify, which package version is this > exactly? There seems to be something missing fro

Re: [Pkg-ia32-libs-maintainers] A security bug in Debian Squeeze libtiff (+ non-updated ia32-libs??)

2012-04-07 Thread Thijs Kinkhorst
Hi, On Sat, April 7, 2012 06:24, Mikulas Patocka wrote: > There is a security bug in Debian Squeeze libtiff 3.9.4-5+sq. Thanks for reporting. Just to clarify, which package version is this exactly? There seems to be something missing from the version number you quote. > BTW. how does Debian secu