Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

libtiff 4.0.3 in thirdparty has 50 security vulnerabilities #4193

Open
chkno opened this issue Dec 22, 2021 · 3 comments
Open

libtiff 4.0.3 in thirdparty has 50 security vulnerabilities #4193

chkno opened this issue Dec 22, 2021 · 3 comments

Comments

@chkno
Copy link

chkno commented Dec 22, 2021

Opentoonz includes libtiff 4.0.3 in thirdparty/. libtiff 4.0.3 is affected by 50 currently known security vulnerabilites.

(See also #3864 and #4119)

@chkno
Copy link
Author

chkno commented Dec 22, 2021

I made a crude attempt at merging opentoonz's 64-bit-support changes into libtiff 4.3.0 and then merging all the security fixes back in here, but I am not familiar with either opentoonz or libtiff, so I wouldn't trust this. :(

@ghost
Copy link

ghost commented Jan 1, 2022

There's a very special reason why opentoonz uses libtiff 4.0.3, I tried to fix it myself, but ultimately gave up seeing it as a futile effort. @RodneyBaker and @shun-iwasawa could give better description about the issues surrounding using libtiff 4.0.3 and why this project is stuck with it until further notice.

@flurick
Copy link
Contributor

flurick commented Nov 25, 2022

Looks like v4.4.0 is the current available release (with various 64bit related changes AKA BigTIFF).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants