The following defect(s) have been fixed in this cumulative patch for the Wind River libtiff:
WIND00212513 Security Advisory - libTIFF - CVE-2010-1411
WIND00218130 Security Advisory - libtiff - CVE-2010-2065
WIND00221134 Security Advisory - LibTIFF - CVE-2010-2483
WIND00221132 Security Advisory - LibTIFF - CVE-2010-2481
WIND00221321 Security Advisory - LibTIFF - CVE-2010-2597
WIND00221319 Security Advisory - LibTIFF - CVE-2010-2595
WIND00221324 Security Advisory - LibTIFF - CVE-2010-2598
WIND00232834 Security Advisory - libtiff - CVE-2010-3087
WIND00266146 Security Advisory - LibTIFF - CVE-2011-1167
WIND00374012 Security Advisory - libtiff - CVE-2012-3401
-----------------------------------------------------------------------------
Change List:
/wrlinux/dist/libtiff/Makefile
/wrlinux/dist/libtiff/patches/tiff-CVE-2012-3401.patch
/wrlinux/dist/libtiff/patches/libtiff-3.7.1-CVE-2010-2598.patch
/wrlinux/dist/libtiff/patches/libtiff-3.7.1-CVE-2010-2595.patch
/wrlinux/dist/libtiff/patches/libtiff-3.7.1-CVE-2010-2065.patch
/wrlinux/dist/libtiff/patches/libtiff-3.7.1-CVE-2010-1411.patch
/wrlinux/dist/libtiff/patches/libtiff-3.7.1-CVE-2010-2481.patch
/wrlinux/dist/libtiff/patches/libtiff-3.7.1-CVE-2011-1167.patch
/wrlinux/dist/libtiff/patches/libtiff-3.7.1-CVE-2010-2597.patch
/wrlinux/dist/libtiff/patches/libtiff-3.7.1-CVE-2010-3087.patch
/wrlinux/dist/libtiff/patches/patches.list
/wrlinux/dist/libtiff/patches/libtiff-3.7.1-CVE-2010-2483.patch
Requires Wind River Linux 2.0 Update Pack 4 (2.0.4) to be installed.
1. Unzip this patch under [install_dir]/updates
2. From the [install_dir]/updates directory, run the command "../maintenance/mtool/mtool_linux"
3. Follow the instructions for installing the point patch.
4. This is a source only patch so you will have to rebuild the libtiff package.
This can be done by executing the command "make -C build libtiff
.distclean"followed by "make -C build libtiff.rebuild"
5. Run "make fs" next
6. Upload the kernel and rootfs into the target and boot it up.
DATE: 21 Nov 2012
REVISION: file WRL_2_0_4-base-tgt-libtiff-20110713-spin1.zip replaced with WRL_2_0_4-base-tgt-libtiff-20121114-spin1.zip and includes fix to defect WIND00374012
DATE: 19 Jul 2011
REVISION: file WRL_2_0_4-base-tgt-libtiff-20101107-spin1.zip replaced with WRL_2_0_4-base-tgt-libtiff-20110713-spin1.zip and includes fix to defect WIND00266146
DATE: 08 Nov 2010
REVISION: file WRL_2_0_4-base-tgt-libtiff-20100801-spin1.zip replaced with WRL_2_0_4-base-tgt-libtiff-20101107-spin1.zip and includes fix to defect WIND00232834
DATE: 03 Aug 2010
REVISION: file WRL_2_0_4-base-tgt-libtiff-20100730-spin1.zip replaced with WRL_2_0_4-base-tgt-libtiff-20100801-spin1.zip and includes fix to defect WIND00221324
DATE: 02 Aug 2010
REVISION: file WRL_2_0_4-base-tgt-libtiff-20100720-spin1.zip replaced with WRL_2_0_4-base-tgt-libtiff-20100730-spin1.zip and includes fix to defect WIND00221134 WIND00221132 WIND00221321 WIND00221319
DATE: 26 July 2010
REVISION: file WRL_2_0_4-base-tgt-libtiff-20100627-spin1.zip replaced with WRL_2_0_4-base-tgt-libtiff-20100720-spin1.zip and includes fix to defect WIND00218130
DATE: 06 July 2010
REVISION: Add file WRL_2_0_4-base-tgt-libtiff-20100627-spin1.zip and includes fix to defect WIND00212513