2020.08.16 13:51 "[Tiff] Disable Old JPEG in libtiff by default!", by Bob Friesenhahn

2020.08.16 14:27 "Re: [Tiff] Disable Old JPEG in libtiff by default!", by John

The libtiff configure script enables support for reading old JPEG by default. I propose that the libtiff default should be to disable support for old JPEG.

I still come across old-style JPEG images occasionally, perhaps once a year. It would be annoying if I had to rebuild software to be able to process them.

You're right that there are security implications, though libtiff is fuzzed so heavily now that I think the risk is small.

John