2005.06.03 13:42 "RE: [Tiff] BitsPerSample buffer overflow - security release?", by Thom DeCarlo
Is there a planned release date for a stable version of libTIFF with a fix for the BitsPerSample stack-based buffer overflow?
You guys fixed the problem in CVS early last month.
Gentoo and Ubuntu have already issued updated packages. We use a binary version of libTIFF embedded in FreeImage, and so can't easily patch our local copy, so ideally you guys would release an update and then we'd get them to release one as well. Do you have a planned release date for the next version?
And maybe someone can get the update into the Cygwin distribution, too?