DESCRIPTION
libtiff[1] is a library for handling TIFF images.
wxGTK[2] is the GTK+2 port of the wxWidgets library, an open source
C++ GUI framework.
This announcement fixes several integer overflow vulnerabilities[3,4]
that were encountered in libtiff by iDefense which could lead to
remote arbitrary code execution.
As wxGTK has a private copy of libtiff's source, it is also fixed by
this announcement.
SOLUTION
It is recommended that all libtiff/wxGTK users upgrade their
packages.
IMPORTANT: all applications linked against libtiff/wxGTK must be
restarted after the upgrade in order to close the vulnerabilities.