UbuntuUpdates.org

Package "tiff"

Name: tiff

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • TIFF manipulation and conversion tools
  • TIFF manipulation and conversion tools

Latest version: 4.7.0-3ubuntu3.1
Release: questing (25.10)
Level: security
Repository: universe

Links



Other versions of "tiff" in Questing

Repository Area Version
base main 4.7.0-3ubuntu3
base universe 4.7.0-3ubuntu3
security main 4.7.0-3ubuntu3.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 4.7.0-3ubuntu3.1 2026-03-23 09:08:19 UTC

  tiff (4.7.0-3ubuntu3.1) questing-security; urgency=medium

  * SECURITY UPDATE: null-pointer dereference
    - debian/patches/CVE-2025-61143.patch: check for null pointer before call
      to TIFFFileName in tools/tiffcrop.c.
    - CVE-2025-61143
  * SECURITY UPDATE: stack buffer overflow
    - debian/patches/CVE-2025-61144.patch: update loop condition to also check
      samples against MAX_SAMPLES in tools/tiffcrop.c.
    - CVE-2025-61144

 -- Ian Constantin <email address hidden> Wed, 18 Mar 2026 10:40:57 +0200

CVE-2025-61143 libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.
CVE-2025-61144 libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.



About   -   Send Feedback to @ubuntu_updates