Bug 216776 - graphics/linux-c6-tiff: update to 3.9.4-21.el6_8
Summary: graphics/linux-c6-tiff: update to 3.9.4-21.el6_8
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Tijl Coosemans
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-02-04 12:53 UTC by Piotr Kubaj
Modified: 2017-02-07 11:38 UTC (History)
1 user (show)

See Also:
bugzilla: maintainer-feedback? (emulation)
pkubaj: merge-quarterly?


Attachments
patch (1.68 KB, patch)
2017-02-04 12:53 UTC, Piotr Kubaj
no flags Details | Diff
security/vuxml patch (2.26 KB, patch)
2017-02-04 12:54 UTC, Piotr Kubaj
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Piotr Kubaj freebsd_committer freebsd_triage 2017-02-04 12:53:55 UTC
Created attachment 179590 [details]
patch

This patch updates the port to the newest version.

Changelog:
* Multiple flaws have been discovered in libtiff. A remote attacker could
exploit these flaws to cause a crash or memory corruption and, possibly, execute
arbitrary code by tricking an application linked against libtiff into processing
specially crafted files. (CVE-2016-9533, CVE-2016-9534, CVE-2016-9535)

* Multiple flaws have been discovered in various libtiff tools (tiff2pdf,
tiffcrop, tiffcp, bmp2tiff). By tricking a user into processing a specially
crafted file, a remote attacker could exploit these flaws to cause a crash or
memory corruption and, possibly, execute arbitrary code with the privileges of
the user running the libtiff tool. (CVE-2015-8870, CVE-2016-5652, CVE-2016-9540,
CVE-2016-9537, CVE-2016-9536)

As such, MFH is necessary.

Builds fine on Poudriere on 10.3.
Comment 1 Piotr Kubaj freebsd_committer freebsd_triage 2017-02-04 12:54:51 UTC
Created attachment 179591 [details]
security/vuxml patch
Comment 2 commit-hook freebsd_committer freebsd_triage 2017-02-06 18:06:36 UTC
A commit references this bug:

Author: tijl
Date: Mon Feb  6 18:05:48 UTC 2017
New revision: 433503
URL: https://svnweb.freebsd.org/changeset/ports/433503

Log:
  Update to 3.9.4-21.el6_8.

  PR:		216776
  Submitted by:	Piotr Kubaj <pkubaj@anongoth.pl>
  MFH:		2017Q1
  Security:	https://rhn.redhat.com/errata/RHSA-2017-0225.html

Changes:
  head/graphics/linux-c6-tiff/Makefile
  head/graphics/linux-c6-tiff/distinfo
Comment 3 commit-hook freebsd_committer freebsd_triage 2017-02-07 11:21:57 UTC
A commit references this bug:

Author: tijl
Date: Tue Feb  7 11:21:44 UTC 2017
New revision: 433540
URL: https://svnweb.freebsd.org/changeset/ports/433540

Log:
  MFH: r433503

  Update to 3.9.4-21.el6_8.

  PR:		216776
  Submitted by:	Piotr Kubaj <pkubaj@anongoth.pl>
  Approved by:	ports-secteam (feld)
  Security:	https://rhn.redhat.com/errata/RHSA-2017-0225.html

Changes:
_U  branches/2017Q1/
  branches/2017Q1/graphics/linux-c6-tiff/Makefile
  branches/2017Q1/graphics/linux-c6-tiff/distinfo.i386
  branches/2017Q1/graphics/linux-c6-tiff/distinfo.x86_64