Issue metadata
Sign in to add a comment
|
Security: libtiff in pdfium may have a security issue
Reported by
resea...@nightwatchcybersecurity.com,
Jun 3 2016
|
||||||||||||||||||||||
Issue description
,
Jun 3 2016
Total of three bugs: https://web.nvd.nist.gov/view/vuln/search-results?adv_search=true&cves=on&cpe_version=cpe:/a:libtiff_project:libtiff:4.0.6 CVE-2016-3186 CVE-2015-8668 CVE-2015-7554
,
Jun 3 2016
Since it's a public CVE, I'm removing the view restrictions. There appear to be no patches for this though, and I'm not familiar enough with tiff to make a confident judgement about whether this actually affects pdfium, or to write a correct patch for it...
,
Jun 3 2016
,
Jun 3 2016
,
Jun 3 2016
hong_zhang, could you please route this security bug to the appropriate person? thanks.
,
Jun 7 2016
,
Jun 7 2016
,
Jun 7 2016
I will. ochange@
,
Jun 8 2016
Additional CVEs with buffer overflows: CVE-2016-5318 CVE-2016-5319 Details: http://www.openwall.com/lists/oss-security/2016/06/07/1
,
Jun 10 2016
Marking this severity-high because at least one (CVE-2015-8668) of these CVEs is a buffer overflow.
,
Jun 10 2016
,
Jun 10 2016
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 10 2016
,
Jun 13 2016
,
Jun 13 2016
,
Jun 13 2016
,
Jun 13 2016
Can you please add the OS label which was affected ? Also, please let us know if this can be tested manually. This is marked as M52 RB-Beta label, hence requesting you to provide you the details so that this can be fixed & merged in to M52 branch for next beta promotion this wednesday.
,
Jun 14 2016
Removing the release block label -- there was no demonstrated reachable vulnerability in this bug report, and the feature in question that uses this library has already been turned off.
,
Jun 16 2016
,
Mar 9 2017
,
Jan 31 2018
We have since updated libtiff to 4.0.8, which I believe has this issue fixed.
,
Feb 8 2018
,
May 10 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 1
,
Nov 12
(the VRP panel declined to award, see comment 19) |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by f...@chromium.org
, Jun 3 2016Owner: och...@chromium.org
Status: Untriaged (was: Unconfirmed)