libtiff-tools - TIFF manipulation and conversion tools

Debian 8 (Jessie)
Debian Main i386
Package filename libtiff-tools_4.0.3-12.3+deb8u5_i386.deb
Package name libtiff-tools
Package version 4.0.3
Package release 12.3+deb8u5
Package architecture i386
Package type deb
Category devel::library graphics role::program use::converting works-with::image works-with::image:raster
License -
Maintainer Ondřej Surý <>
Download size 270.26 KB
Installed size 619.00 KB
libtiff is a library providing support for the Tag Image File Format
(TIFF), a widely used format for storing image data.  This package
includes tools for converting TIFF images to and from other formats
and tools for doing simple manipulations of TIFF images.  See also


libc6 >= 2.7
libjbig0 >= 2.0
libjpeg62-turbo >= 1.3.1
liblzma5 >= 5.1.1alpha+20110809
libtiff5 >= 4.0.3
zlib1g >= 1:1.1.4


Binary Package libtiff-tools_4.0.3-12.3+deb8u5_i386.deb
Source Package tiff

Install Howto

  1. Update the package index:
    # sudo apt-get update
  2. Install libtiff-tools deb package:
    # sudo apt-get install libtiff-tools




2018-01-26 - Moritz Muehlenhoff <>
tiff (4.0.3-12.3+deb8u5) jessie-security; urgency=high
[ Laszlo Boszormenyi (GCS) ]
* Fix CVE-2017-11335: heap based buffer write overflow in tiff2pdf
(closes: #868513).
* Fix CVE-2017-12944: OOM prevention in TIFFReadDirEntryArray()
(closes: #872607).
* Fix CVE-2017-13726: reachable assertion abort in TIFFWriteDirectorySec()
(closes: #873880).
* Fix CVE-2017-13727: reachable assertion abort in
TIFFWriteDirectoryTagSubifd() (closes: #873879).
* Fix CVE-2017-18013: NULL pointer dereference in TIFFPrintDirectory()
(closes: #885985).
* Fix CVE-2017-9935: heap-based buffer overflow in the t2p_write_pdf()
function (closes: #866109).
[ Moritz Muehlenhoff ]
* CVE-2016-10371
2017-07-02 - Laszlo Boszormenyi (GCS) <>
tiff (4.0.3-12.3+deb8u4) jessie-security; urgency=high
* Backport fix for the following vulnerabilities:
- CVE-2017-9403: fix memory leak in non DEFER_STRILE_LOAD mode,
- CVE-2017-9404: memory leak vulnerability was found in the function
- CVE-2016-10095 and CVE-2017-9147: add _TIFFCheckFieldIsValidForCodec()
and use it in TIFFReadDirectory() (closes: #850316, #863185),
- CVE-2017-9936: memory leak in error code path of JBIGDecode()
(closes: #866113),
- prevent out of memory in gtTileContig() on corrupted files,
- CVE-2017-10688, assertion failure in TIFFWriteDirectoryTagCheckedXXXX()
(closes: #866611).
* Add required _TIFFCheckFieldIsValidForCodec@LIBTIFF_4.0 and
_TIFFReadEncodedStripAndAllocBuffer@LIBTIFF_4.0 symbols to the
libtiff5 package.
2017-04-21 - Laszlo Boszormenyi (GCS) <>
tiff (4.0.3-12.3+deb8u3) jessie-security; urgency=high
* Backport fix for the following vulnerabilities:
- CVE-2014-8127 and CVE-2016-3658: out-of-bounds read in the tiffset tool,
- CVE-2016-9535: replace assertions by runtime checks to avoid assertions
in debug mode, or buffer overflows in release mode,
- CVE-2016-10266: divide-by-zero in TIFFReadEncodedStrip,
- CVE-2016-10267: divide-by-zero in OJPEGDecodeRaw,
- CVE-2016-10269: heap-based buffer overflow in _TIFFmemcpy,
- CVE-2016-10270: heap-based buffer overflow in TIFFFillStrip,
- CVE-2017-5225: heap buffer overflow via a crafted BitsPerSample value,
- CVE-2017-7592: left-shift undefined behavior issue in putagreytile,
- CVE-2017-7593: unitialized-memory access from tif_rawdata,
- CVE-2017-7594: leak in OJPEGReadHeaderInfoSecTablesAcTable,
- CVE-2017-7595: divide-by-zero in JPEGSetupEncode,
- CVE-2017-7596, CVE-2017-7597, CVE-2017-7598, CVE-2017-7599,
CVE-2017-7600, CVE-2017-7601 and CVE-2017-7602: multiple UBSAN crashes.
* Add required _TIFFcalloc@LIBTIFF_4.0 symbol to the libtiff5 package.
[ Tobias Lippert <> ]
* Fix a regression introduced by patch CVE-2014-8128-5 where enabling
compression of tif files results in corrupt files
(closes: #783555, #818360).

