Debian 9918 Published by

A tiff security update has been released for Debian GNU/Linux 8 Extended LTS to address two vulnerabilities.



ELA-447-1 tiff security update

Package tiff
Version 4.0.3-12.3+deb8u11
Related CVEs CVE-2020-35523 CVE-2020-35524

Two vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service or the execution of arbitrary code if malformed image files are processed.

For Debian 8 jessie, these problems have been fixed in version 4.0.3-12.3+deb8u11.

We recommend that you upgrade your tiff packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-447-1 tiff security update