135b7f035SBob Friesenhahn<HTML> 235b7f035SBob Friesenhahn<HEAD> 335b7f035SBob Friesenhahn<TITLE> 435b7f035SBob Friesenhahn Changes in TIFF v4.0.7 535b7f035SBob Friesenhahn</TITLE> 635b7f035SBob Friesenhahn</HEAD> 735b7f035SBob Friesenhahn 835b7f035SBob Friesenhahn<BODY BGCOLOR=white> 935b7f035SBob Friesenhahn<FONT FACE="Helvetica, Arial, Sans"> 1035b7f035SBob Friesenhahn 1135b7f035SBob Friesenhahn<BASEFONT SIZE=4> 1235b7f035SBob Friesenhahn<B><FONT SIZE=+3>T</FONT>IFF <FONT SIZE=+2>C</FONT>HANGE <FONT SIZE=+2>I</FONT>NFORMATION</B> 1335b7f035SBob Friesenhahn<BASEFONT SIZE=3> 1435b7f035SBob Friesenhahn 1535b7f035SBob Friesenhahn<UL> 1635b7f035SBob Friesenhahn<HR SIZE=4 WIDTH=65% ALIGN=left> 1735b7f035SBob Friesenhahn<B>Current Version</B>: v4.0.7<BR> 1835b7f035SBob Friesenhahn<B>Previous Version</B>: <A HREF=v4.0.6.html>v4.0.6</a><BR> 1935b7f035SBob Friesenhahn<B>Master FTP Site</B>: <A HREF="ftp://download.osgeo.org/libtiff"> 2035b7f035SBob Friesenhahndownload.osgeo.org</a>, directory pub/libtiff</A><BR> 2135b7f035SBob Friesenhahn<B>Master HTTP Site #1</B>: <A HREF="http://www.simplesystems.org/libtiff/"> 2235b7f035SBob Friesenhahnhttp://www.simplesystems.org/libtiff/</a><BR> 2335b7f035SBob Friesenhahn<B>Master HTTP Site #2</B>: <A HREF="http://libtiff.maptools.org/"> 2435b7f035SBob Friesenhahnhttp://libtiff.maptools.org/</a> 2535b7f035SBob Friesenhahn<HR SIZE=4 WIDTH=65% ALIGN=left> 2635b7f035SBob Friesenhahn</UL> 2735b7f035SBob Friesenhahn 2835b7f035SBob Friesenhahn<P> 2935b7f035SBob FriesenhahnThis document describes the changes made to the software between the 3035b7f035SBob Friesenhahn<I>previous</I> and <I>current</I> versions (see above). If you don't 3135b7f035SBob Friesenhahnfind something listed here, then it was not done in this timeframe, or 3235b7f035SBob Friesenhahnit was not considered important enough to be mentioned. The following 3335b7f035SBob Friesenhahninformation is located here: 3435b7f035SBob Friesenhahn<UL> 3535b7f035SBob Friesenhahn<LI><A HREF="#highlights">Major Changes</A> 3635b7f035SBob Friesenhahn<LI><A HREF="#configure">Changes in the software configuration</A> 3735b7f035SBob Friesenhahn<LI><A HREF="#libtiff">Changes in libtiff</A> 3835b7f035SBob Friesenhahn<LI><A HREF="#tools">Changes in the tools</A> 3935b7f035SBob Friesenhahn<LI><A HREF="#contrib">Changes in the contrib area</A> 4035b7f035SBob Friesenhahn</UL> 4135b7f035SBob Friesenhahn<p> 4235b7f035SBob Friesenhahn<P><HR WIDTH=65% ALIGN=left> 4335b7f035SBob Friesenhahn 4435b7f035SBob Friesenhahn<!---------------------------------------------------------------------------> 4535b7f035SBob Friesenhahn 4635b7f035SBob Friesenhahn<A NAME="highlights"><B><FONT SIZE=+3>M</FONT>AJOR CHANGES:</B></A> 4735b7f035SBob Friesenhahn 4835b7f035SBob Friesenhahn<UL> 4935b7f035SBob Friesenhahn 5035b7f035SBob Friesenhahn <LI> The libtiff tools bmp2tiff, gif2tiff, ras2tiff, sgi2tiff, 5135b7f035SBob Friesenhahn sgisv, and ycbcr are completely removed from the distribution. 5235b7f035SBob Friesenhahn These tools were written in the late 1980s and early 1990s for 5335b7f035SBob Friesenhahn test and demonstration purposes. In some cases the tools were 5435b7f035SBob Friesenhahn never updated to support updates to the file format, or the 5535b7f035SBob Friesenhahn file formats are now rarely used. In all cases these tools 5635b7f035SBob Friesenhahn increased the libtiff security and maintenance exposure beyond 5735b7f035SBob Friesenhahn the value offered by the tool. 5835b7f035SBob Friesenhahn 5935b7f035SBob Friesenhahn</UL> 6035b7f035SBob Friesenhahn 6135b7f035SBob Friesenhahn 6235b7f035SBob Friesenhahn<P><HR WIDTH=65% ALIGN=left> 6335b7f035SBob Friesenhahn<!---------------------------------------------------------------------------> 6435b7f035SBob Friesenhahn 6535b7f035SBob Friesenhahn<A NAME="configure"><B><FONT SIZE=+3>C</FONT>HANGES IN THE SOFTWARE CONFIGURATION:</B></A> 6635b7f035SBob Friesenhahn 6735b7f035SBob Friesenhahn<UL> 6835b7f035SBob Friesenhahn 6935b7f035SBob Friesenhahn <LI> None 7035b7f035SBob Friesenhahn 7135b7f035SBob Friesenhahn</UL> 7235b7f035SBob Friesenhahn 7335b7f035SBob Friesenhahn<P><HR WIDTH=65% ALIGN=left> 7435b7f035SBob Friesenhahn 7535b7f035SBob Friesenhahn<!---------------------------------------------------------------------------> 7635b7f035SBob Friesenhahn 7735b7f035SBob Friesenhahn<A NAME="libtiff"><B><FONT SIZE=+3>C</FONT>HANGES IN LIBTIFF:</B></A> 7835b7f035SBob Friesenhahn 7935b7f035SBob Friesenhahn<UL> 8035b7f035SBob Friesenhahn 81*884f9736SBob Friesenhahn <LI> libtiff/tif_dirread.c: in TIFFFetchNormalTag(), do not 82*884f9736SBob Friesenhahn dereference NULL pointer when values of tags with 83*884f9736SBob Friesenhahn TIFF_SETGET_C16_ASCII / TIFF_SETGET_C32_ASCII access are 84*884f9736SBob Friesenhahn 0-byte arrays. Fixes 85*884f9736SBob Friesenhahn http://bugzilla.maptools.org/show_bug.cgi?id=2593 (regression 86*884f9736SBob Friesenhahn introduced by previous fix done on 2016-11-11 for 87*884f9736SBob Friesenhahn CVE-2016-9297). Reported by Henri Salo. Assigned as 88*884f9736SBob Friesenhahn CVE-2016-9448 89*884f9736SBob Friesenhahn 9035b7f035SBob Friesenhahn <LI> libtiff/tif_aux.c: fix crash in TIFFVGetFieldDefaulted() when 9135b7f035SBob Friesenhahn requesting Predictor tag and that the zip/lzw codec is not 9235b7f035SBob Friesenhahn configured. Fixes 9335b7f035SBob Friesenhahn http://bugzilla.maptools.org/show_bug.cgi?id=2591 9435b7f035SBob Friesenhahn 9535b7f035SBob Friesenhahn <LI> libtiff/tif_dirread.c: in TIFFFetchNormalTag(), make sure 9635b7f035SBob Friesenhahn that values of tags with TIFF_SETGET_C16_ASCII / 9735b7f035SBob Friesenhahn TIFF_SETGET_C32_ASCII access are null terminated, to avoid 9835b7f035SBob Friesenhahn potential read outside buffer in _TIFFPrintField(). Fixes 9935b7f035SBob Friesenhahn http://bugzilla.maptools.org/show_bug.cgi?id=2590 10035b7f035SBob Friesenhahn 10135b7f035SBob Friesenhahn <LI> libtiff/tif_dirread.c: reject images with OJPEG compression 10235b7f035SBob Friesenhahn that have no TileOffsets/StripOffsets tag, when OJPEG 10335b7f035SBob Friesenhahn compression is disabled. Prevent null pointer dereference in 10435b7f035SBob Friesenhahn TIFFReadRawStrip1() and other functions that expect 10535b7f035SBob Friesenhahn td_stripbytecount to be non NULL. Fixes 10635b7f035SBob Friesenhahn http://bugzilla.maptools.org/show_bug.cgi?id=2585 10735b7f035SBob Friesenhahn 10835b7f035SBob Friesenhahn <LI> libtiff/tif_strip.c: make TIFFNumberOfStrips() return the 10935b7f035SBob Friesenhahn td->td_nstrips value when it is non-zero, instead of 11035b7f035SBob Friesenhahn recomputing it. This is needed in TIFF_STRIPCHOP mode where 11135b7f035SBob Friesenhahn td_nstrips is modified. Fixes a read outsize of array in 11235b7f035SBob Friesenhahn tiffsplit (or other utilities using TIFFNumberOfStrips()). 11335b7f035SBob Friesenhahn Fixes http://bugzilla.maptools.org/show_bug.cgi?id=2587 11435b7f035SBob Friesenhahn (CVE-2016-9273) 11535b7f035SBob Friesenhahn 11635b7f035SBob Friesenhahn <LI> libtiff/tif_predict.h, libtiff/tif_predict.c: Replace 11735b7f035SBob Friesenhahn assertions by runtime checks to avoid assertions in debug 11835b7f035SBob Friesenhahn mode, or buffer overflows in release mode. Can happen when 11935b7f035SBob Friesenhahn dealing with unusual tile size like YCbCr with 12035b7f035SBob Friesenhahn subsampling. Reported as MSVR 35105 by Axel Souchet & Vishal 12135b7f035SBob Friesenhahn Chauhan from the MSRC Vulnerabilities & Mitigations 12235b7f035SBob Friesenhahn 12335b7f035SBob Friesenhahn <LI> libtiff/tif_dir.c: discard values of SMinSampleValue and 12435b7f035SBob Friesenhahn SMaxSampleValue when they have been read and the value of 12535b7f035SBob Friesenhahn SamplesPerPixel is changed afterwards (like when reading a 12635b7f035SBob Friesenhahn OJPEG compressed image with a missing SamplesPerPixel tag, and 12735b7f035SBob Friesenhahn whose photometric is RGB or YCbCr, forcing SamplesPerPixel 12835b7f035SBob Friesenhahn being 3). Otherwise when rewriting the directory (for example 12935b7f035SBob Friesenhahn with tiffset, we will expect 3 values whereas the array had 13035b7f035SBob Friesenhahn been allocated with just one), thus causing a out of bound 13135b7f035SBob Friesenhahn read access. Fixes 13235b7f035SBob Friesenhahn http://bugzilla.maptools.org/show_bug.cgi?id=2500 13335b7f035SBob Friesenhahn (CVE-2014-8127, duplicate: CVE-2016-3658) 13435b7f035SBob Friesenhahn 13535b7f035SBob Friesenhahn <LI> libtiff/tif_dirwrite.c: avoid null pointer dereference on 13635b7f035SBob Friesenhahn td_stripoffset when writing directory, if FIELD_STRIPOFFSETS 13735b7f035SBob Friesenhahn was artificially set for a hack case in OJPEG case. Fixes 13835b7f035SBob Friesenhahn http://bugzilla.maptools.org/show_bug.cgi?id=2500 13935b7f035SBob Friesenhahn (CVE-2014-8127, duplicate: CVE-2016-3658) 14035b7f035SBob Friesenhahn 14135b7f035SBob Friesenhahn <LI> libtiff/tif_getimage.c (TIFFRGBAImageOK): Reject attempts to 14235b7f035SBob Friesenhahn read floating point images. 14335b7f035SBob Friesenhahn 14435b7f035SBob Friesenhahn <LI> libtiff/tif_predict.c (PredictorSetup): Enforce 14535b7f035SBob Friesenhahn bits-per-sample requirements of floating point predictor (3). 14635b7f035SBob Friesenhahn Fixes CVE-2016-3622 "Divide By Zero in the tiff2rgba tool." 14735b7f035SBob Friesenhahn 14835b7f035SBob Friesenhahn <LI> libtiff/tif_pixarlog.c: fix out-of-bounds write vulnerabilities 14935b7f035SBob Friesenhahn in heap allocated buffers. Reported as MSVR 35094. Discovered by 15035b7f035SBob Friesenhahn Axel Souchet and Vishal Chauhan from the MSRC Vulnerabilities & 15135b7f035SBob Friesenhahn Mitigations team. 15235b7f035SBob Friesenhahn 15335b7f035SBob Friesenhahn <LI> libtiff/tif_write.c: fix issue in error code path of 15435b7f035SBob Friesenhahn TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp 15535b7f035SBob Friesenhahn members. I'm not completely sure if that could happen in 15635b7f035SBob Friesenhahn practice outside of the odd behaviour of t2p_seekproc() of 15735b7f035SBob Friesenhahn tiff2pdf). The report points that a better fix could be to 15835b7f035SBob Friesenhahn check the return value of TIFFFlushData1() in places where it 15935b7f035SBob Friesenhahn isn't done currently, but it seems this patch is enough. 16035b7f035SBob Friesenhahn Reported as MSVR 35095. Discovered by Axel Souchet & Vishal 16135b7f035SBob Friesenhahn Chauhan & Suha Can from the MSRC Vulnerabilities & Mitigations 16235b7f035SBob Friesenhahn team. 16335b7f035SBob Friesenhahn 16435b7f035SBob Friesenhahn <LI> libtiff/tif_pixarlog.c: Fix write buffer overflow in 16535b7f035SBob Friesenhahn PixarLogEncode if more input samples are provided than 16635b7f035SBob Friesenhahn expected by PixarLogSetupEncode. Idea based on 16735b7f035SBob Friesenhahn libtiff-CVE-2016-3990.patch from 16835b7f035SBob Friesenhahn libtiff-4.0.3-25.el7_2.src.rpm by Nikola Forro, but with 16935b7f035SBob Friesenhahn different and simpler check. (bugzilla #2544) 17035b7f035SBob Friesenhahn 17135b7f035SBob Friesenhahn <LI> libtiff/tif_read.c: Fix out-of-bounds read on memory-mapped 17235b7f035SBob Friesenhahn files in TIFFReadRawStrip1() and TIFFReadRawTile1() when 17335b7f035SBob Friesenhahn stripoffset is beyond tmsize_t max value (reported by Mathias 17435b7f035SBob Friesenhahn Svensson) 17535b7f035SBob Friesenhahn 17635b7f035SBob Friesenhahn <LI> libtiff/tif_read.c: make TIFFReadEncodedStrip() and 17735b7f035SBob Friesenhahn TIFFReadEncodedTile() directly use user provided buffer when 17835b7f035SBob Friesenhahn no compression (and other conditions) to save a memcpy() 17935b7f035SBob Friesenhahn 18035b7f035SBob Friesenhahn <LI> libtiff/tif_write.c: make TIFFWriteEncodedStrip() and 18135b7f035SBob Friesenhahn TIFFWriteEncodedTile() directly use user provided buffer when 18235b7f035SBob Friesenhahn no compression to save a memcpy(). 18335b7f035SBob Friesenhahn 18435b7f035SBob Friesenhahn <LI> libtiff/tif_luv.c: validate that for COMPRESSION_SGILOG and 18535b7f035SBob Friesenhahn PHOTOMETRIC_LOGL, there is only one sample per pixel. Avoid 18635b7f035SBob Friesenhahn potential invalid memory write on corrupted/unexpected images 18735b7f035SBob Friesenhahn when using the TIFFRGBAImageBegin() interface (reported by 18835b7f035SBob Friesenhahn Clay Wood) 18935b7f035SBob Friesenhahn 19035b7f035SBob Friesenhahn <LI> libtiff/tif_pixarlog.c: fix potential buffer write overrun in 19135b7f035SBob Friesenhahn PixarLogDecode() on corrupted/unexpected images (reported by 19235b7f035SBob Friesenhahn Mathias Svensson) (CVE-2016-5875) 19335b7f035SBob Friesenhahn 19435b7f035SBob Friesenhahn <LI> libtiff/libtiff.def: Added _TIFFMultiply32 and 19535b7f035SBob Friesenhahn _TIFFMultiply64 to libtiff.def 19635b7f035SBob Friesenhahn 19735b7f035SBob Friesenhahn <LI> libtiff/tif_config.vc.h (HAVE_SNPRINTF): Add a '1' to the 19835b7f035SBob Friesenhahn HAVE_SNPRINTF definition. 19935b7f035SBob Friesenhahn 20035b7f035SBob Friesenhahn <LI> libtiff/tif_config.vc.h (HAVE_SNPRINTF): Applied patch by 20135b7f035SBob Friesenhahn Edward Lam to define HAVE_SNPRINTF for Visual Studio 2015. 20235b7f035SBob Friesenhahn 20335b7f035SBob Friesenhahn <LI> libtiff/tif_dirread.c: when compiled with DEFER_STRILE_LOAD, 20435b7f035SBob Friesenhahn fix regression, introduced on 2014-12-23, when reading a 20535b7f035SBob Friesenhahn one-strip file without a StripByteCounts tag. GDAL #6490 20635b7f035SBob Friesenhahn 20735b7f035SBob Friesenhahn <LI> libtiff/*: upstream typo fixes (mostly contributed by Kurt 20835b7f035SBob Friesenhahn Schwehr) coming from GDAL internal libtiff 20935b7f035SBob Friesenhahn 21035b7f035SBob Friesenhahn <LI> libtiff/tif_fax3.h: make Param member of TIFFFaxTabEnt 21135b7f035SBob Friesenhahn structure a uint16 to reduce size of the binary. 21235b7f035SBob Friesenhahn 21335b7f035SBob Friesenhahn <LI> libtiff/tif_read.c, tif_dirread.c: fix indentation issues 21435b7f035SBob Friesenhahn raised by GCC 6 -Wmisleading-indentation 21535b7f035SBob Friesenhahn 21635b7f035SBob Friesenhahn <LI> libtiff/tif_pixarlog.c: avoid zlib error messages to pass a 21735b7f035SBob Friesenhahn NULL string to %s formatter, which is undefined behaviour in 21835b7f035SBob Friesenhahn sprintf(). 21935b7f035SBob Friesenhahn 22035b7f035SBob Friesenhahn <LI> libtiff/tif_next.c: fix potential out-of-bound write in NeXTDecode() 22135b7f035SBob Friesenhahn triggered by http://lcamtuf.coredump.cx/afl/vulns/libtiff5.tif 22235b7f035SBob Friesenhahn (bugzilla #2508) 22335b7f035SBob Friesenhahn 22435b7f035SBob Friesenhahn <LI> libtiff/tif_luv.c: fix potential out-of-bound writes in 22535b7f035SBob Friesenhahn decode functions in non debug builds by replacing assert()s by 22635b7f035SBob Friesenhahn regular if checks (bugzilla #2522). Fix potential 22735b7f035SBob Friesenhahn out-of-bound reads in case of short input data. 22835b7f035SBob Friesenhahn 22935b7f035SBob Friesenhahn <LI> libtiff/tif_getimage.c: fix out-of-bound reads in 23035b7f035SBob Friesenhahn TIFFRGBAImage interface in case of unsupported values of 23135b7f035SBob Friesenhahn SamplesPerPixel/ExtraSamples for LogLUV / CIELab. Add explicit 23235b7f035SBob Friesenhahn call to TIFFRGBAImageOK() in TIFFRGBAImageBegin(). Fix 23335b7f035SBob Friesenhahn CVE-2015-8665 reported by limingxing and CVE-2015-8683 23435b7f035SBob Friesenhahn reported by zzf of Alibaba. 23535b7f035SBob Friesenhahn 23635b7f035SBob Friesenhahn <LI> libtiff/tif_dirread.c: workaround false positive warning of 23735b7f035SBob Friesenhahn Clang Static Analyzer about null pointer dereference in 23835b7f035SBob Friesenhahn TIFFCheckDirOffset(). 23935b7f035SBob Friesenhahn 24035b7f035SBob Friesenhahn <LI> libtiff/tif_fax3.c: remove dead assignment in 24135b7f035SBob Friesenhahn Fax3PutEOLgdal(). Found by Clang Static Analyzer 24235b7f035SBob Friesenhahn 24335b7f035SBob Friesenhahn <LI> libtiff/tif_dirwrite.c: fix truncation to 32 bit of file 24435b7f035SBob Friesenhahn offsets in TIFFLinkDirectory() and TIFFWriteDirectorySec() 24535b7f035SBob Friesenhahn when aligning directory offsets on a even offset (affects 24635b7f035SBob Friesenhahn BigTIFF). This was a regression of the changeset of 24735b7f035SBob Friesenhahn 2015-10-19. 24835b7f035SBob Friesenhahn 24935b7f035SBob Friesenhahn <LI> libtiff/tif_write.c: TIFFWriteEncodedStrip() and 25035b7f035SBob Friesenhahn TIFFWriteEncodedTile() should return -1 in case of failure of 25135b7f035SBob Friesenhahn tif_encodestrip() as documented 25235b7f035SBob Friesenhahn 25335b7f035SBob Friesenhahn <LI> libtiff/tif_dumpmode.c: DumpModeEncode() should return 0 in 25435b7f035SBob Friesenhahn case of failure so that the above mentionned functions detect 25535b7f035SBob Friesenhahn the error. 25635b7f035SBob Friesenhahn 25735b7f035SBob Friesenhahn <LI> libtiff/*.c: fix MSVC warnings related to cast shortening and 25835b7f035SBob Friesenhahn assignment within conditional expression 25935b7f035SBob Friesenhahn 26035b7f035SBob Friesenhahn <LI> libtiff/*.c: fix clang -Wshorten-64-to-32 warnings 26135b7f035SBob Friesenhahn 26235b7f035SBob Friesenhahn <LI> libtiff/tif_dirread.c: prevent reading ColorMap or 26335b7f035SBob Friesenhahn TransferFunction if BitsPerPixel > 24, so as to avoid huge 26435b7f035SBob Friesenhahn memory allocation and file read attempts 26535b7f035SBob Friesenhahn 26635b7f035SBob Friesenhahn <LI> libtiff/tif_dirread.c: remove duplicated assignment (reported 26735b7f035SBob Friesenhahn by Clang static analyzer) 26835b7f035SBob Friesenhahn 26935b7f035SBob Friesenhahn <LI> libtiff/tif_dir.c, libtiff/tif_dirinfo.c, 27035b7f035SBob Friesenhahn libtiff/tif_compress.c, libtiff/tif_jpeg_12.c: suppress 27135b7f035SBob Friesenhahn warnings about 'no previous declaration/prototype' 27235b7f035SBob Friesenhahn 27335b7f035SBob Friesenhahn <LI> libtiff/tiffiop.h, libtiff/tif_dirwrite.c: suffix constants 27435b7f035SBob Friesenhahn by U to fix 'warning: negative integer implicitly converted to 27535b7f035SBob Friesenhahn unsigned type' warning (part of -Wconversion) 27635b7f035SBob Friesenhahn 27735b7f035SBob Friesenhahn <LI> libtiff/tif_dir.c, libtiff/tif_dirread.c, 27835b7f035SBob Friesenhahn libtiff/tif_getimage.c, libtiff/tif_print.c: fix -Wshadow 27935b7f035SBob Friesenhahn warnings (only in libtiff/) 28035b7f035SBob Friesenhahn 28135b7f035SBob Friesenhahn</UL> 28235b7f035SBob Friesenhahn 28335b7f035SBob Friesenhahn<P><HR WIDTH=65% ALIGN=left> 28435b7f035SBob Friesenhahn 28535b7f035SBob Friesenhahn<!--------------------------------------------------------------------------> 28635b7f035SBob Friesenhahn 28735b7f035SBob Friesenhahn<A NAME="tools"><B><FONT SIZE=+3>C</FONT>HANGES IN THE TOOLS:</B></A> 28835b7f035SBob Friesenhahn 28935b7f035SBob Friesenhahn<UL> 29035b7f035SBob Friesenhahn 29135b7f035SBob Friesenhahn <LI> tools/Makefile.am: The libtiff tools bmp2tiff, gif2tiff, 29235b7f035SBob Friesenhahn ras2tiff, sgi2tiff, sgisv, and ycbcr are completely removed 29335b7f035SBob Friesenhahn from the distribution. The libtiff tools rgb2ycbcr and 29435b7f035SBob Friesenhahn thumbnail are only built in the build tree for testing. Old 29535b7f035SBob Friesenhahn files are put in new 'archive' subdirectory of the source 29635b7f035SBob Friesenhahn repository, but not in distribution archives. These changes 29735b7f035SBob Friesenhahn are made in order to lessen the maintenance burden. 29835b7f035SBob Friesenhahn 29935b7f035SBob Friesenhahn <LI> tools/tiff2pdf.c: avoid undefined behaviour related to 30035b7f035SBob Friesenhahn overlapping of source and destination buffer in memcpy() call 30135b7f035SBob Friesenhahn in t2p_sample_rgbaa_to_rgb() Fixes 30235b7f035SBob Friesenhahn http://bugzilla.maptools.org/show_bug.cgi?id=2577 30335b7f035SBob Friesenhahn 30435b7f035SBob Friesenhahn <LI> tools/tiff2pdf.c: fix potential integer overflows on 32 bit 30535b7f035SBob Friesenhahn builds in t2p_read_tiff_size() Fixes 30635b7f035SBob Friesenhahn http://bugzilla.maptools.org/show_bug.cgi?id=2576 30735b7f035SBob Friesenhahn 30835b7f035SBob Friesenhahn <LI> tools/fax2tiff.c: fix segfault when specifying -r without 30935b7f035SBob Friesenhahn argument. Patch by Yuriy M. Kaminskiy. Fixes 31035b7f035SBob Friesenhahn http://bugzilla.maptools.org/show_bug.cgi?id=2572 31135b7f035SBob Friesenhahn 31235b7f035SBob Friesenhahn <LI> tools/tiffinfo.c: fix out-of-bound read on some tiled images. 31335b7f035SBob Friesenhahn (http://bugzilla.maptools.org/show_bug.cgi?id=2517) 31435b7f035SBob Friesenhahn 3156ff69f46SBob Friesenhahn <LI> tools/tiffcrop.c: fix multiple uint32 overflows in 3166ff69f46SBob Friesenhahn writeBufferToSeparateStrips(), writeBufferToContigTiles() and 3176ff69f46SBob Friesenhahn writeBufferToSeparateTiles() that could cause heap buffer 3186ff69f46SBob Friesenhahn overflows. Reported by Henri Salo from Nixu Corporation. 3196ff69f46SBob Friesenhahn Fixes http://bugzilla.maptools.org/show_bug.cgi?id=2592 3206ff69f46SBob Friesenhahn 32135b7f035SBob Friesenhahn <LI> tools/tiffcrop.c: fix out-of-bound read of up to 3 bytes in 32235b7f035SBob Friesenhahn readContigTilesIntoBuffer(). Reported as MSVR 35092 by Axel 32335b7f035SBob Friesenhahn Souchet & Vishal Chauhan from the MSRC Vulnerabilities & 32435b7f035SBob Friesenhahn Mitigations team. 32535b7f035SBob Friesenhahn 32635b7f035SBob Friesenhahn <LI> tools/tiff2pdf.c: fix write buffer overflow of 2 bytes on 32735b7f035SBob Friesenhahn JPEG compressed images. Reported by Tyler Bohan of Cisco Talos 32835b7f035SBob Friesenhahn as TALOS-CAN-0187 / CVE-2016-5652. Also prevents writing 2 32935b7f035SBob Friesenhahn extra uninitialized bytes to the file stream. 33035b7f035SBob Friesenhahn 33135b7f035SBob Friesenhahn <LI> tools/tiffcp.c: fix out-of-bounds write on tiled images with odd 33235b7f035SBob Friesenhahn tile width vs image width. Reported as MSVR 35103 33335b7f035SBob Friesenhahn by Axel Souchet and Vishal Chauhan from the MSRC Vulnerabilities & 33435b7f035SBob Friesenhahn Mitigations team. 33535b7f035SBob Friesenhahn 33635b7f035SBob Friesenhahn <LI> tools/tiff2pdf.c: fix read -largely- outsize of buffer in 33735b7f035SBob Friesenhahn t2p_readwrite_pdf_image_tile(), causing crash, when reading a 33835b7f035SBob Friesenhahn JPEG compressed image with TIFFTAG_JPEGTABLES length being 33935b7f035SBob Friesenhahn one. Reported as MSVR 35101 by Axel Souchet and Vishal 34035b7f035SBob Friesenhahn Chauhan from the MSRC Vulnerabilities & Mitigations team. 34135b7f035SBob Friesenhahn 34235b7f035SBob Friesenhahn <LI> tools/tiffcp.c: fix read of undefined variable in case of 34335b7f035SBob Friesenhahn missing required tags. Found on test case of MSVR 35100. 34435b7f035SBob Friesenhahn 34535b7f035SBob Friesenhahn <LI> tools/tiffcrop.c: fix read of undefined buffer in 34635b7f035SBob Friesenhahn readContigStripsIntoBuffer() due to uint16 overflow. Probably 34735b7f035SBob Friesenhahn not a security issue but I can be wrong. Reported as MSVR 34835b7f035SBob Friesenhahn 35100 by Axel Souchet from the MSRC Vulnerabilities & 34935b7f035SBob Friesenhahn Mitigations team. 35035b7f035SBob Friesenhahn 35135b7f035SBob Friesenhahn <LI> tools/tiffcrop.c: fix various out-of-bounds write 35235b7f035SBob Friesenhahn vulnerabilities in heap or stack allocated buffers. Reported 35335b7f035SBob Friesenhahn as MSVR 35093, MSVR 35096 and MSVR 35097. Discovered by Axel 35435b7f035SBob Friesenhahn Souchet and Vishal Chauhan from the MSRC Vulnerabilities & 35535b7f035SBob Friesenhahn Mitigations team. 35635b7f035SBob Friesenhahn 35735b7f035SBob Friesenhahn <LI> tools/tiff2pdf.c: fix out-of-bounds write vulnerabilities in 35835b7f035SBob Friesenhahn heap allocate buffer in t2p_process_jpeg_strip(). Reported as 35935b7f035SBob Friesenhahn MSVR 35098. Discovered by Axel Souchet and Vishal Chauhan from 36035b7f035SBob Friesenhahn the MSRC Vulnerabilities & Mitigations team. 36135b7f035SBob Friesenhahn 36235b7f035SBob Friesenhahn <LI> tools/tiff2bw.c: fix weight computation that could result of 36335b7f035SBob Friesenhahn color value overflow (no security implication). Fix bugzilla 36435b7f035SBob Friesenhahn #2550. Patch by Frank Freudenberg. 36535b7f035SBob Friesenhahn 36635b7f035SBob Friesenhahn <LI> tools/rgb2ycbcr.c: validate values of -v and -h parameters to 36735b7f035SBob Friesenhahn avoid potential divide by zero. Fixes CVE-2016-3623 (bugzilla #2569) 36835b7f035SBob Friesenhahn 36935b7f035SBob Friesenhahn <LI> tools/tiffcrop.c: Fix out-of-bounds write in loadImage(). 37035b7f035SBob Friesenhahn From patch libtiff-CVE-2016-3991.patch from 37135b7f035SBob Friesenhahn libtiff-4.0.3-25.el7_2.src.rpm by Nikola Forro (bugzilla 37235b7f035SBob Friesenhahn #2543) 37335b7f035SBob Friesenhahn 37435b7f035SBob Friesenhahn <LI> tools/tiff2rgba.c: Fix integer overflow in size of allocated 37535b7f035SBob Friesenhahn buffer, when -b mode is enabled, that could result in 37635b7f035SBob Friesenhahn out-of-bounds write. Based initially on patch 37735b7f035SBob Friesenhahn tiff-CVE-2016-3945.patch from libtiff-4.0.3-25.el7_2.src.rpm 37835b7f035SBob Friesenhahn by Nikola Forro, with correction for invalid tests that 37935b7f035SBob Friesenhahn rejected valid files. (bugzilla #2545) 38035b7f035SBob Friesenhahn 38135b7f035SBob Friesenhahn <LI> tools/tiffcrop.c: Avoid access outside of stack allocated 38235b7f035SBob Friesenhahn array on a tiled separate TIFF with more than 8 samples per 38335b7f035SBob Friesenhahn pixel. Reported by Kaixiang Zhang of the Cloud Security Team, 38435b7f035SBob Friesenhahn Qihoo 360 (CVE-2016-5321 / CVE-2016-5323 , bugzilla #2558 / 38535b7f035SBob Friesenhahn #2559) 38635b7f035SBob Friesenhahn 38735b7f035SBob Friesenhahn <LI> tools/tiffdump.c: fix a few misaligned 64-bit reads warned by 38835b7f035SBob Friesenhahn -fsanitize 38935b7f035SBob Friesenhahn 390*884f9736SBob Friesenhahn <LI> tools/tiffdump.c (ReadDirectory): Remove uint32 cast to 391*884f9736SBob Friesenhahn _TIFFmalloc() argument which resulted in Coverity report. 392*884f9736SBob Friesenhahn Added more mutiplication overflow checks. 393*884f9736SBob Friesenhahn 39435b7f035SBob Friesenhahn</UL> 39535b7f035SBob Friesenhahn 39635b7f035SBob Friesenhahn<P><HR WIDTH=65% ALIGN=left> 39735b7f035SBob Friesenhahn 39835b7f035SBob Friesenhahn<!---------------------------------------------------------------------------> 39935b7f035SBob Friesenhahn 40035b7f035SBob Friesenhahn<A NAME="contrib"><B><FONT SIZE=+3>C</FONT>HANGES IN THE CONTRIB AREA:</B></A> 40135b7f035SBob Friesenhahn 40235b7f035SBob Friesenhahn<UL> 40335b7f035SBob Friesenhahn 40435b7f035SBob Friesenhahn <LI> None 40535b7f035SBob Friesenhahn 40635b7f035SBob Friesenhahn</UL> 40735b7f035SBob Friesenhahn 408*884f9736SBob FriesenhahnLast updated $Date: 2016-11-19 17:47:40 $. 40935b7f035SBob Friesenhahn 41035b7f035SBob Friesenhahn</BODY> 41135b7f035SBob Friesenhahn</HTML> 412