xref: /libtiff-4.0.7/html/v4.0.7.html (revision 884f9736)
135b7f035SBob Friesenhahn<HTML>
235b7f035SBob Friesenhahn<HEAD>
335b7f035SBob Friesenhahn<TITLE>
435b7f035SBob Friesenhahn	Changes in TIFF v4.0.7
535b7f035SBob Friesenhahn</TITLE>
635b7f035SBob Friesenhahn</HEAD>
735b7f035SBob Friesenhahn
835b7f035SBob Friesenhahn<BODY BGCOLOR=white>
935b7f035SBob Friesenhahn<FONT FACE="Helvetica, Arial, Sans">
1035b7f035SBob Friesenhahn
1135b7f035SBob Friesenhahn<BASEFONT SIZE=4>
1235b7f035SBob Friesenhahn<B><FONT SIZE=+3>T</FONT>IFF <FONT SIZE=+2>C</FONT>HANGE <FONT SIZE=+2>I</FONT>NFORMATION</B>
1335b7f035SBob Friesenhahn<BASEFONT SIZE=3>
1435b7f035SBob Friesenhahn
1535b7f035SBob Friesenhahn<UL>
1635b7f035SBob Friesenhahn<HR SIZE=4 WIDTH=65% ALIGN=left>
1735b7f035SBob Friesenhahn<B>Current Version</B>: v4.0.7<BR>
1835b7f035SBob Friesenhahn<B>Previous Version</B>: <A HREF=v4.0.6.html>v4.0.6</a><BR>
1935b7f035SBob Friesenhahn<B>Master FTP Site</B>: <A HREF="ftp://download.osgeo.org/libtiff">
2035b7f035SBob Friesenhahndownload.osgeo.org</a>, directory pub/libtiff</A><BR>
2135b7f035SBob Friesenhahn<B>Master HTTP Site #1</B>: <A HREF="http://www.simplesystems.org/libtiff/">
2235b7f035SBob Friesenhahnhttp://www.simplesystems.org/libtiff/</a><BR>
2335b7f035SBob Friesenhahn<B>Master HTTP Site #2</B>: <A HREF="http://libtiff.maptools.org/">
2435b7f035SBob Friesenhahnhttp://libtiff.maptools.org/</a>
2535b7f035SBob Friesenhahn<HR SIZE=4 WIDTH=65% ALIGN=left>
2635b7f035SBob Friesenhahn</UL>
2735b7f035SBob Friesenhahn
2835b7f035SBob Friesenhahn<P>
2935b7f035SBob FriesenhahnThis document describes the changes made to the software between the
3035b7f035SBob Friesenhahn<I>previous</I> and <I>current</I> versions (see above).  If you don't
3135b7f035SBob Friesenhahnfind something listed here, then it was not done in this timeframe, or
3235b7f035SBob Friesenhahnit was not considered important enough to be mentioned.  The following
3335b7f035SBob Friesenhahninformation is located here:
3435b7f035SBob Friesenhahn<UL>
3535b7f035SBob Friesenhahn<LI><A HREF="#highlights">Major Changes</A>
3635b7f035SBob Friesenhahn<LI><A HREF="#configure">Changes in the software configuration</A>
3735b7f035SBob Friesenhahn<LI><A HREF="#libtiff">Changes in libtiff</A>
3835b7f035SBob Friesenhahn<LI><A HREF="#tools">Changes in the tools</A>
3935b7f035SBob Friesenhahn<LI><A HREF="#contrib">Changes in the contrib area</A>
4035b7f035SBob Friesenhahn</UL>
4135b7f035SBob Friesenhahn<p>
4235b7f035SBob Friesenhahn<P><HR WIDTH=65% ALIGN=left>
4335b7f035SBob Friesenhahn
4435b7f035SBob Friesenhahn<!--------------------------------------------------------------------------->
4535b7f035SBob Friesenhahn
4635b7f035SBob Friesenhahn<A NAME="highlights"><B><FONT SIZE=+3>M</FONT>AJOR CHANGES:</B></A>
4735b7f035SBob Friesenhahn
4835b7f035SBob Friesenhahn<UL>
4935b7f035SBob Friesenhahn
5035b7f035SBob Friesenhahn	<LI> The libtiff tools bmp2tiff, gif2tiff, ras2tiff, sgi2tiff,
5135b7f035SBob Friesenhahn        sgisv, and ycbcr are completely removed from the distribution.
5235b7f035SBob Friesenhahn        These tools were written in the late 1980s and early 1990s for
5335b7f035SBob Friesenhahn        test and demonstration purposes.  In some cases the tools were
5435b7f035SBob Friesenhahn        never updated to support updates to the file format, or the
5535b7f035SBob Friesenhahn        file formats are now rarely used.  In all cases these tools
5635b7f035SBob Friesenhahn        increased the libtiff security and maintenance exposure beyond
5735b7f035SBob Friesenhahn        the value offered by the tool.
5835b7f035SBob Friesenhahn
5935b7f035SBob Friesenhahn</UL>
6035b7f035SBob Friesenhahn
6135b7f035SBob Friesenhahn
6235b7f035SBob Friesenhahn<P><HR WIDTH=65% ALIGN=left>
6335b7f035SBob Friesenhahn<!--------------------------------------------------------------------------->
6435b7f035SBob Friesenhahn
6535b7f035SBob Friesenhahn<A NAME="configure"><B><FONT SIZE=+3>C</FONT>HANGES IN THE SOFTWARE CONFIGURATION:</B></A>
6635b7f035SBob Friesenhahn
6735b7f035SBob Friesenhahn<UL>
6835b7f035SBob Friesenhahn
6935b7f035SBob Friesenhahn  <LI> None
7035b7f035SBob Friesenhahn
7135b7f035SBob Friesenhahn</UL>
7235b7f035SBob Friesenhahn
7335b7f035SBob Friesenhahn<P><HR WIDTH=65% ALIGN=left>
7435b7f035SBob Friesenhahn
7535b7f035SBob Friesenhahn<!--------------------------------------------------------------------------->
7635b7f035SBob Friesenhahn
7735b7f035SBob Friesenhahn<A NAME="libtiff"><B><FONT SIZE=+3>C</FONT>HANGES IN LIBTIFF:</B></A>
7835b7f035SBob Friesenhahn
7935b7f035SBob Friesenhahn<UL>
8035b7f035SBob Friesenhahn
81*884f9736SBob Friesenhahn    <LI> libtiff/tif_dirread.c: in TIFFFetchNormalTag(), do not
82*884f9736SBob Friesenhahn        dereference NULL pointer when values of tags with
83*884f9736SBob Friesenhahn        TIFF_SETGET_C16_ASCII / TIFF_SETGET_C32_ASCII access are
84*884f9736SBob Friesenhahn        0-byte arrays.  Fixes
85*884f9736SBob Friesenhahn        http://bugzilla.maptools.org/show_bug.cgi?id=2593 (regression
86*884f9736SBob Friesenhahn        introduced by previous fix done on 2016-11-11 for
87*884f9736SBob Friesenhahn        CVE-2016-9297).  Reported by Henri Salo. Assigned as
88*884f9736SBob Friesenhahn        CVE-2016-9448
89*884f9736SBob Friesenhahn
9035b7f035SBob Friesenhahn    <LI> libtiff/tif_aux.c: fix crash in TIFFVGetFieldDefaulted() when
9135b7f035SBob Friesenhahn        requesting Predictor tag and that the zip/lzw codec is not
9235b7f035SBob Friesenhahn        configured.  Fixes
9335b7f035SBob Friesenhahn        http://bugzilla.maptools.org/show_bug.cgi?id=2591
9435b7f035SBob Friesenhahn
9535b7f035SBob Friesenhahn    <LI> libtiff/tif_dirread.c: in TIFFFetchNormalTag(), make sure
9635b7f035SBob Friesenhahn        that values of tags with TIFF_SETGET_C16_ASCII /
9735b7f035SBob Friesenhahn        TIFF_SETGET_C32_ASCII access are null terminated, to avoid
9835b7f035SBob Friesenhahn        potential read outside buffer in _TIFFPrintField().  Fixes
9935b7f035SBob Friesenhahn        http://bugzilla.maptools.org/show_bug.cgi?id=2590
10035b7f035SBob Friesenhahn
10135b7f035SBob Friesenhahn    <LI> libtiff/tif_dirread.c: reject images with OJPEG compression
10235b7f035SBob Friesenhahn        that have no TileOffsets/StripOffsets tag, when OJPEG
10335b7f035SBob Friesenhahn        compression is disabled. Prevent null pointer dereference in
10435b7f035SBob Friesenhahn        TIFFReadRawStrip1() and other functions that expect
10535b7f035SBob Friesenhahn        td_stripbytecount to be non NULL.  Fixes
10635b7f035SBob Friesenhahn        http://bugzilla.maptools.org/show_bug.cgi?id=2585
10735b7f035SBob Friesenhahn
10835b7f035SBob Friesenhahn    <LI> libtiff/tif_strip.c: make TIFFNumberOfStrips() return the
10935b7f035SBob Friesenhahn        td->td_nstrips value when it is non-zero, instead of
11035b7f035SBob Friesenhahn        recomputing it. This is needed in TIFF_STRIPCHOP mode where
11135b7f035SBob Friesenhahn        td_nstrips is modified. Fixes a read outsize of array in
11235b7f035SBob Friesenhahn        tiffsplit (or other utilities using TIFFNumberOfStrips()).
11335b7f035SBob Friesenhahn        Fixes http://bugzilla.maptools.org/show_bug.cgi?id=2587
11435b7f035SBob Friesenhahn        (CVE-2016-9273)
11535b7f035SBob Friesenhahn
11635b7f035SBob Friesenhahn    <LI> libtiff/tif_predict.h, libtiff/tif_predict.c: Replace
11735b7f035SBob Friesenhahn        assertions by runtime checks to avoid assertions in debug
11835b7f035SBob Friesenhahn        mode, or buffer overflows in release mode. Can happen when
11935b7f035SBob Friesenhahn        dealing with unusual tile size like YCbCr with
12035b7f035SBob Friesenhahn        subsampling. Reported as MSVR 35105 by Axel Souchet & Vishal
12135b7f035SBob Friesenhahn        Chauhan from the MSRC Vulnerabilities & Mitigations
12235b7f035SBob Friesenhahn
12335b7f035SBob Friesenhahn    <LI> libtiff/tif_dir.c: discard values of SMinSampleValue and
12435b7f035SBob Friesenhahn        SMaxSampleValue when they have been read and the value of
12535b7f035SBob Friesenhahn        SamplesPerPixel is changed afterwards (like when reading a
12635b7f035SBob Friesenhahn        OJPEG compressed image with a missing SamplesPerPixel tag, and
12735b7f035SBob Friesenhahn        whose photometric is RGB or YCbCr, forcing SamplesPerPixel
12835b7f035SBob Friesenhahn        being 3). Otherwise when rewriting the directory (for example
12935b7f035SBob Friesenhahn        with tiffset, we will expect 3 values whereas the array had
13035b7f035SBob Friesenhahn        been allocated with just one), thus causing a out of bound
13135b7f035SBob Friesenhahn        read access.  Fixes
13235b7f035SBob Friesenhahn        http://bugzilla.maptools.org/show_bug.cgi?id=2500
13335b7f035SBob Friesenhahn        (CVE-2014-8127, duplicate: CVE-2016-3658)
13435b7f035SBob Friesenhahn
13535b7f035SBob Friesenhahn    <LI> libtiff/tif_dirwrite.c: avoid null pointer dereference on
13635b7f035SBob Friesenhahn        td_stripoffset when writing directory, if FIELD_STRIPOFFSETS
13735b7f035SBob Friesenhahn        was artificially set for a hack case in OJPEG case.  Fixes
13835b7f035SBob Friesenhahn        http://bugzilla.maptools.org/show_bug.cgi?id=2500
13935b7f035SBob Friesenhahn        (CVE-2014-8127, duplicate: CVE-2016-3658)
14035b7f035SBob Friesenhahn
14135b7f035SBob Friesenhahn    <LI> libtiff/tif_getimage.c (TIFFRGBAImageOK): Reject attempts to
14235b7f035SBob Friesenhahn        read floating point images.
14335b7f035SBob Friesenhahn
14435b7f035SBob Friesenhahn    <LI> libtiff/tif_predict.c (PredictorSetup): Enforce
14535b7f035SBob Friesenhahn        bits-per-sample requirements of floating point predictor (3).
14635b7f035SBob Friesenhahn        Fixes CVE-2016-3622 "Divide By Zero in the tiff2rgba tool."
14735b7f035SBob Friesenhahn
14835b7f035SBob Friesenhahn    <LI> libtiff/tif_pixarlog.c: fix out-of-bounds write vulnerabilities
14935b7f035SBob Friesenhahn        in heap allocated buffers. Reported as MSVR 35094. Discovered by
15035b7f035SBob Friesenhahn        Axel Souchet and Vishal Chauhan from the MSRC Vulnerabilities &
15135b7f035SBob Friesenhahn        Mitigations team.
15235b7f035SBob Friesenhahn
15335b7f035SBob Friesenhahn    <LI> libtiff/tif_write.c: fix issue in error code path of
15435b7f035SBob Friesenhahn        TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp
15535b7f035SBob Friesenhahn        members. I'm not completely sure if that could happen in
15635b7f035SBob Friesenhahn        practice outside of the odd behaviour of t2p_seekproc() of
15735b7f035SBob Friesenhahn        tiff2pdf). The report points that a better fix could be to
15835b7f035SBob Friesenhahn        check the return value of TIFFFlushData1() in places where it
15935b7f035SBob Friesenhahn        isn't done currently, but it seems this patch is enough.
16035b7f035SBob Friesenhahn        Reported as MSVR 35095. Discovered by Axel Souchet & Vishal
16135b7f035SBob Friesenhahn        Chauhan & Suha Can from the MSRC Vulnerabilities & Mitigations
16235b7f035SBob Friesenhahn        team.
16335b7f035SBob Friesenhahn
16435b7f035SBob Friesenhahn    <LI> libtiff/tif_pixarlog.c: Fix write buffer overflow in
16535b7f035SBob Friesenhahn        PixarLogEncode if more input samples are provided than
16635b7f035SBob Friesenhahn        expected by PixarLogSetupEncode.  Idea based on
16735b7f035SBob Friesenhahn        libtiff-CVE-2016-3990.patch from
16835b7f035SBob Friesenhahn        libtiff-4.0.3-25.el7_2.src.rpm by Nikola Forro, but with
16935b7f035SBob Friesenhahn        different and simpler check. (bugzilla #2544)
17035b7f035SBob Friesenhahn
17135b7f035SBob Friesenhahn    <LI> libtiff/tif_read.c: Fix out-of-bounds read on memory-mapped
17235b7f035SBob Friesenhahn        files in TIFFReadRawStrip1() and TIFFReadRawTile1() when
17335b7f035SBob Friesenhahn        stripoffset is beyond tmsize_t max value (reported by Mathias
17435b7f035SBob Friesenhahn        Svensson)
17535b7f035SBob Friesenhahn
17635b7f035SBob Friesenhahn    <LI> libtiff/tif_read.c: make TIFFReadEncodedStrip() and
17735b7f035SBob Friesenhahn        TIFFReadEncodedTile() directly use user provided buffer when
17835b7f035SBob Friesenhahn        no compression (and other conditions) to save a memcpy()
17935b7f035SBob Friesenhahn
18035b7f035SBob Friesenhahn    <LI> libtiff/tif_write.c: make TIFFWriteEncodedStrip() and
18135b7f035SBob Friesenhahn        TIFFWriteEncodedTile() directly use user provided buffer when
18235b7f035SBob Friesenhahn        no compression to save a memcpy().
18335b7f035SBob Friesenhahn
18435b7f035SBob Friesenhahn    <LI> libtiff/tif_luv.c: validate that for COMPRESSION_SGILOG and
18535b7f035SBob Friesenhahn        PHOTOMETRIC_LOGL, there is only one sample per pixel. Avoid
18635b7f035SBob Friesenhahn        potential invalid memory write on corrupted/unexpected images
18735b7f035SBob Friesenhahn        when using the TIFFRGBAImageBegin() interface (reported by
18835b7f035SBob Friesenhahn        Clay Wood)
18935b7f035SBob Friesenhahn
19035b7f035SBob Friesenhahn    <LI> libtiff/tif_pixarlog.c: fix potential buffer write overrun in
19135b7f035SBob Friesenhahn        PixarLogDecode() on corrupted/unexpected images (reported by
19235b7f035SBob Friesenhahn        Mathias Svensson) (CVE-2016-5875)
19335b7f035SBob Friesenhahn
19435b7f035SBob Friesenhahn    <LI> libtiff/libtiff.def: Added _TIFFMultiply32 and
19535b7f035SBob Friesenhahn        _TIFFMultiply64 to libtiff.def
19635b7f035SBob Friesenhahn
19735b7f035SBob Friesenhahn     <LI> libtiff/tif_config.vc.h (HAVE_SNPRINTF): Add a '1' to the
19835b7f035SBob Friesenhahn        HAVE_SNPRINTF definition.
19935b7f035SBob Friesenhahn
20035b7f035SBob Friesenhahn    <LI> libtiff/tif_config.vc.h (HAVE_SNPRINTF): Applied patch by
20135b7f035SBob Friesenhahn        Edward Lam to define HAVE_SNPRINTF for Visual Studio 2015.
20235b7f035SBob Friesenhahn
20335b7f035SBob Friesenhahn    <LI> libtiff/tif_dirread.c: when compiled with DEFER_STRILE_LOAD,
20435b7f035SBob Friesenhahn        fix regression, introduced on 2014-12-23, when reading a
20535b7f035SBob Friesenhahn        one-strip file without a StripByteCounts tag. GDAL #6490
20635b7f035SBob Friesenhahn
20735b7f035SBob Friesenhahn    <LI> libtiff/*: upstream typo fixes (mostly contributed by Kurt
20835b7f035SBob Friesenhahn        Schwehr) coming from GDAL internal libtiff
20935b7f035SBob Friesenhahn
21035b7f035SBob Friesenhahn    <LI> libtiff/tif_fax3.h: make Param member of TIFFFaxTabEnt
21135b7f035SBob Friesenhahn        structure a uint16 to reduce size of the binary.
21235b7f035SBob Friesenhahn
21335b7f035SBob Friesenhahn    <LI> libtiff/tif_read.c, tif_dirread.c: fix indentation issues
21435b7f035SBob Friesenhahn        raised by GCC 6 -Wmisleading-indentation
21535b7f035SBob Friesenhahn
21635b7f035SBob Friesenhahn    <LI> libtiff/tif_pixarlog.c: avoid zlib error messages to pass a
21735b7f035SBob Friesenhahn        NULL string to %s formatter, which is undefined behaviour in
21835b7f035SBob Friesenhahn        sprintf().
21935b7f035SBob Friesenhahn
22035b7f035SBob Friesenhahn    <LI> libtiff/tif_next.c: fix potential out-of-bound write in NeXTDecode()
22135b7f035SBob Friesenhahn        triggered by http://lcamtuf.coredump.cx/afl/vulns/libtiff5.tif
22235b7f035SBob Friesenhahn        (bugzilla #2508)
22335b7f035SBob Friesenhahn
22435b7f035SBob Friesenhahn    <LI> libtiff/tif_luv.c: fix potential out-of-bound writes in
22535b7f035SBob Friesenhahn        decode functions in non debug builds by replacing assert()s by
22635b7f035SBob Friesenhahn        regular if checks (bugzilla #2522).  Fix potential
22735b7f035SBob Friesenhahn        out-of-bound reads in case of short input data.
22835b7f035SBob Friesenhahn
22935b7f035SBob Friesenhahn    <LI> libtiff/tif_getimage.c: fix out-of-bound reads in
23035b7f035SBob Friesenhahn        TIFFRGBAImage interface in case of unsupported values of
23135b7f035SBob Friesenhahn        SamplesPerPixel/ExtraSamples for LogLUV / CIELab. Add explicit
23235b7f035SBob Friesenhahn        call to TIFFRGBAImageOK() in TIFFRGBAImageBegin(). Fix
23335b7f035SBob Friesenhahn        CVE-2015-8665 reported by limingxing and CVE-2015-8683
23435b7f035SBob Friesenhahn        reported by zzf of Alibaba.
23535b7f035SBob Friesenhahn
23635b7f035SBob Friesenhahn    <LI> libtiff/tif_dirread.c: workaround false positive warning of
23735b7f035SBob Friesenhahn        Clang Static Analyzer about null pointer dereference in
23835b7f035SBob Friesenhahn        TIFFCheckDirOffset().
23935b7f035SBob Friesenhahn
24035b7f035SBob Friesenhahn    <LI> libtiff/tif_fax3.c: remove dead assignment in
24135b7f035SBob Friesenhahn        Fax3PutEOLgdal(). Found by Clang Static Analyzer
24235b7f035SBob Friesenhahn
24335b7f035SBob Friesenhahn    <LI> libtiff/tif_dirwrite.c: fix truncation to 32 bit of file
24435b7f035SBob Friesenhahn        offsets in TIFFLinkDirectory() and TIFFWriteDirectorySec()
24535b7f035SBob Friesenhahn        when aligning directory offsets on a even offset (affects
24635b7f035SBob Friesenhahn        BigTIFF). This was a regression of the changeset of
24735b7f035SBob Friesenhahn        2015-10-19.
24835b7f035SBob Friesenhahn
24935b7f035SBob Friesenhahn    <LI> libtiff/tif_write.c: TIFFWriteEncodedStrip() and
25035b7f035SBob Friesenhahn        TIFFWriteEncodedTile() should return -1 in case of failure of
25135b7f035SBob Friesenhahn        tif_encodestrip() as documented
25235b7f035SBob Friesenhahn
25335b7f035SBob Friesenhahn    <LI> libtiff/tif_dumpmode.c: DumpModeEncode() should return 0 in
25435b7f035SBob Friesenhahn        case of failure so that the above mentionned functions detect
25535b7f035SBob Friesenhahn        the error.
25635b7f035SBob Friesenhahn
25735b7f035SBob Friesenhahn    <LI> libtiff/*.c: fix MSVC warnings related to cast shortening and
25835b7f035SBob Friesenhahn        assignment within conditional expression
25935b7f035SBob Friesenhahn
26035b7f035SBob Friesenhahn    <LI> libtiff/*.c: fix clang -Wshorten-64-to-32 warnings
26135b7f035SBob Friesenhahn
26235b7f035SBob Friesenhahn    <LI> libtiff/tif_dirread.c: prevent reading ColorMap or
26335b7f035SBob Friesenhahn        TransferFunction if BitsPerPixel > 24, so as to avoid huge
26435b7f035SBob Friesenhahn        memory allocation and file read attempts
26535b7f035SBob Friesenhahn
26635b7f035SBob Friesenhahn    <LI> libtiff/tif_dirread.c: remove duplicated assignment (reported
26735b7f035SBob Friesenhahn        by Clang static analyzer)
26835b7f035SBob Friesenhahn
26935b7f035SBob Friesenhahn    <LI> libtiff/tif_dir.c, libtiff/tif_dirinfo.c,
27035b7f035SBob Friesenhahn        libtiff/tif_compress.c, libtiff/tif_jpeg_12.c: suppress
27135b7f035SBob Friesenhahn        warnings about 'no previous declaration/prototype'
27235b7f035SBob Friesenhahn
27335b7f035SBob Friesenhahn    <LI> libtiff/tiffiop.h, libtiff/tif_dirwrite.c: suffix constants
27435b7f035SBob Friesenhahn        by U to fix 'warning: negative integer implicitly converted to
27535b7f035SBob Friesenhahn        unsigned type' warning (part of -Wconversion)
27635b7f035SBob Friesenhahn
27735b7f035SBob Friesenhahn    <LI> libtiff/tif_dir.c, libtiff/tif_dirread.c,
27835b7f035SBob Friesenhahn          libtiff/tif_getimage.c, libtiff/tif_print.c: fix -Wshadow
27935b7f035SBob Friesenhahn          warnings (only in libtiff/)
28035b7f035SBob Friesenhahn
28135b7f035SBob Friesenhahn</UL>
28235b7f035SBob Friesenhahn
28335b7f035SBob Friesenhahn<P><HR WIDTH=65% ALIGN=left>
28435b7f035SBob Friesenhahn
28535b7f035SBob Friesenhahn<!-------------------------------------------------------------------------->
28635b7f035SBob Friesenhahn
28735b7f035SBob Friesenhahn<A NAME="tools"><B><FONT SIZE=+3>C</FONT>HANGES IN THE TOOLS:</B></A>
28835b7f035SBob Friesenhahn
28935b7f035SBob Friesenhahn<UL>
29035b7f035SBob Friesenhahn
29135b7f035SBob Friesenhahn    <LI> tools/Makefile.am: The libtiff tools bmp2tiff, gif2tiff,
29235b7f035SBob Friesenhahn        ras2tiff, sgi2tiff, sgisv, and ycbcr are completely removed
29335b7f035SBob Friesenhahn        from the distribution.  The libtiff tools rgb2ycbcr and
29435b7f035SBob Friesenhahn        thumbnail are only built in the build tree for testing.  Old
29535b7f035SBob Friesenhahn        files are put in new 'archive' subdirectory of the source
29635b7f035SBob Friesenhahn        repository, but not in distribution archives.  These changes
29735b7f035SBob Friesenhahn        are made in order to lessen the maintenance burden.
29835b7f035SBob Friesenhahn
29935b7f035SBob Friesenhahn    <LI> tools/tiff2pdf.c: avoid undefined behaviour related to
30035b7f035SBob Friesenhahn        overlapping of source and destination buffer in memcpy() call
30135b7f035SBob Friesenhahn        in t2p_sample_rgbaa_to_rgb() Fixes
30235b7f035SBob Friesenhahn        http://bugzilla.maptools.org/show_bug.cgi?id=2577
30335b7f035SBob Friesenhahn
30435b7f035SBob Friesenhahn    <LI> tools/tiff2pdf.c: fix potential integer overflows on 32 bit
30535b7f035SBob Friesenhahn        builds in t2p_read_tiff_size() Fixes
30635b7f035SBob Friesenhahn        http://bugzilla.maptools.org/show_bug.cgi?id=2576
30735b7f035SBob Friesenhahn
30835b7f035SBob Friesenhahn    <LI> tools/fax2tiff.c: fix segfault when specifying -r without
30935b7f035SBob Friesenhahn        argument. Patch by Yuriy M. Kaminskiy.  Fixes
31035b7f035SBob Friesenhahn        http://bugzilla.maptools.org/show_bug.cgi?id=2572
31135b7f035SBob Friesenhahn
31235b7f035SBob Friesenhahn    <LI> tools/tiffinfo.c: fix out-of-bound read on some tiled images.
31335b7f035SBob Friesenhahn        (http://bugzilla.maptools.org/show_bug.cgi?id=2517)
31435b7f035SBob Friesenhahn
3156ff69f46SBob Friesenhahn    <LI> tools/tiffcrop.c: fix multiple uint32 overflows in
3166ff69f46SBob Friesenhahn        writeBufferToSeparateStrips(), writeBufferToContigTiles() and
3176ff69f46SBob Friesenhahn        writeBufferToSeparateTiles() that could cause heap buffer
3186ff69f46SBob Friesenhahn        overflows.  Reported by Henri Salo from Nixu Corporation.
3196ff69f46SBob Friesenhahn        Fixes http://bugzilla.maptools.org/show_bug.cgi?id=2592
3206ff69f46SBob Friesenhahn
32135b7f035SBob Friesenhahn    <LI> tools/tiffcrop.c: fix out-of-bound read of up to 3 bytes in
32235b7f035SBob Friesenhahn        readContigTilesIntoBuffer(). Reported as MSVR 35092 by Axel
32335b7f035SBob Friesenhahn        Souchet & Vishal Chauhan from the MSRC Vulnerabilities &
32435b7f035SBob Friesenhahn        Mitigations team.
32535b7f035SBob Friesenhahn
32635b7f035SBob Friesenhahn    <LI> tools/tiff2pdf.c: fix write buffer overflow of 2 bytes on
32735b7f035SBob Friesenhahn        JPEG compressed images. Reported by Tyler Bohan of Cisco Talos
32835b7f035SBob Friesenhahn        as TALOS-CAN-0187 / CVE-2016-5652.  Also prevents writing 2
32935b7f035SBob Friesenhahn        extra uninitialized bytes to the file stream.
33035b7f035SBob Friesenhahn
33135b7f035SBob Friesenhahn    <LI> tools/tiffcp.c: fix out-of-bounds write on tiled images with odd
33235b7f035SBob Friesenhahn        tile width vs image width. Reported as MSVR 35103
33335b7f035SBob Friesenhahn        by Axel Souchet and Vishal Chauhan from the MSRC Vulnerabilities &
33435b7f035SBob Friesenhahn        Mitigations team.
33535b7f035SBob Friesenhahn
33635b7f035SBob Friesenhahn    <LI> tools/tiff2pdf.c: fix read -largely- outsize of buffer in
33735b7f035SBob Friesenhahn        t2p_readwrite_pdf_image_tile(), causing crash, when reading a
33835b7f035SBob Friesenhahn        JPEG compressed image with TIFFTAG_JPEGTABLES length being
33935b7f035SBob Friesenhahn        one.  Reported as MSVR 35101 by Axel Souchet and Vishal
34035b7f035SBob Friesenhahn        Chauhan from the MSRC Vulnerabilities & Mitigations team.
34135b7f035SBob Friesenhahn
34235b7f035SBob Friesenhahn    <LI> tools/tiffcp.c: fix read of undefined variable in case of
34335b7f035SBob Friesenhahn        missing required tags. Found on test case of MSVR 35100.
34435b7f035SBob Friesenhahn
34535b7f035SBob Friesenhahn    <LI> tools/tiffcrop.c: fix read of undefined buffer in
34635b7f035SBob Friesenhahn        readContigStripsIntoBuffer() due to uint16 overflow. Probably
34735b7f035SBob Friesenhahn        not a security issue but I can be wrong. Reported as MSVR
34835b7f035SBob Friesenhahn        35100 by Axel Souchet from the MSRC Vulnerabilities &
34935b7f035SBob Friesenhahn        Mitigations team.
35035b7f035SBob Friesenhahn
35135b7f035SBob Friesenhahn    <LI> tools/tiffcrop.c: fix various out-of-bounds write
35235b7f035SBob Friesenhahn        vulnerabilities in heap or stack allocated buffers. Reported
35335b7f035SBob Friesenhahn        as MSVR 35093, MSVR 35096 and MSVR 35097. Discovered by Axel
35435b7f035SBob Friesenhahn        Souchet and Vishal Chauhan from the MSRC Vulnerabilities &
35535b7f035SBob Friesenhahn        Mitigations team.
35635b7f035SBob Friesenhahn
35735b7f035SBob Friesenhahn    <LI> tools/tiff2pdf.c: fix out-of-bounds write vulnerabilities in
35835b7f035SBob Friesenhahn        heap allocate buffer in t2p_process_jpeg_strip(). Reported as
35935b7f035SBob Friesenhahn        MSVR 35098. Discovered by Axel Souchet and Vishal Chauhan from
36035b7f035SBob Friesenhahn        the MSRC Vulnerabilities & Mitigations team.
36135b7f035SBob Friesenhahn
36235b7f035SBob Friesenhahn    <LI> tools/tiff2bw.c: fix weight computation that could result of
36335b7f035SBob Friesenhahn        color value overflow (no security implication). Fix bugzilla
36435b7f035SBob Friesenhahn        #2550.  Patch by Frank Freudenberg.
36535b7f035SBob Friesenhahn
36635b7f035SBob Friesenhahn    <LI> tools/rgb2ycbcr.c: validate values of -v and -h parameters to
36735b7f035SBob Friesenhahn        avoid potential divide by zero. Fixes CVE-2016-3623 (bugzilla #2569)
36835b7f035SBob Friesenhahn
36935b7f035SBob Friesenhahn    <LI> tools/tiffcrop.c: Fix out-of-bounds write in loadImage().
37035b7f035SBob Friesenhahn        From patch libtiff-CVE-2016-3991.patch from
37135b7f035SBob Friesenhahn        libtiff-4.0.3-25.el7_2.src.rpm by Nikola Forro (bugzilla
37235b7f035SBob Friesenhahn        #2543)
37335b7f035SBob Friesenhahn
37435b7f035SBob Friesenhahn    <LI> tools/tiff2rgba.c: Fix integer overflow in size of allocated
37535b7f035SBob Friesenhahn        buffer, when -b mode is enabled, that could result in
37635b7f035SBob Friesenhahn        out-of-bounds write. Based initially on patch
37735b7f035SBob Friesenhahn        tiff-CVE-2016-3945.patch from libtiff-4.0.3-25.el7_2.src.rpm
37835b7f035SBob Friesenhahn        by Nikola Forro, with correction for invalid tests that
37935b7f035SBob Friesenhahn        rejected valid files. (bugzilla #2545)
38035b7f035SBob Friesenhahn
38135b7f035SBob Friesenhahn    <LI> tools/tiffcrop.c: Avoid access outside of stack allocated
38235b7f035SBob Friesenhahn        array on a tiled separate TIFF with more than 8 samples per
38335b7f035SBob Friesenhahn        pixel.  Reported by Kaixiang Zhang of the Cloud Security Team,
38435b7f035SBob Friesenhahn        Qihoo 360 (CVE-2016-5321 / CVE-2016-5323 , bugzilla #2558 /
38535b7f035SBob Friesenhahn        #2559)
38635b7f035SBob Friesenhahn
38735b7f035SBob Friesenhahn    <LI> tools/tiffdump.c: fix a few misaligned 64-bit reads warned by
38835b7f035SBob Friesenhahn        -fsanitize
38935b7f035SBob Friesenhahn
390*884f9736SBob Friesenhahn    <LI> tools/tiffdump.c (ReadDirectory): Remove uint32 cast to
391*884f9736SBob Friesenhahn        _TIFFmalloc() argument which resulted in Coverity report.
392*884f9736SBob Friesenhahn        Added more mutiplication overflow checks.
393*884f9736SBob Friesenhahn
39435b7f035SBob Friesenhahn</UL>
39535b7f035SBob Friesenhahn
39635b7f035SBob Friesenhahn<P><HR WIDTH=65% ALIGN=left>
39735b7f035SBob Friesenhahn
39835b7f035SBob Friesenhahn<!--------------------------------------------------------------------------->
39935b7f035SBob Friesenhahn
40035b7f035SBob Friesenhahn<A NAME="contrib"><B><FONT SIZE=+3>C</FONT>HANGES IN THE CONTRIB AREA:</B></A>
40135b7f035SBob Friesenhahn
40235b7f035SBob Friesenhahn<UL>
40335b7f035SBob Friesenhahn
40435b7f035SBob Friesenhahn  <LI> None
40535b7f035SBob Friesenhahn
40635b7f035SBob Friesenhahn</UL>
40735b7f035SBob Friesenhahn
408*884f9736SBob FriesenhahnLast updated $Date: 2016-11-19 17:47:40 $.
40935b7f035SBob Friesenhahn
41035b7f035SBob Friesenhahn</BODY>
41135b7f035SBob Friesenhahn</HTML>
412