Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 20: FEDORA-2015-8706 Critical Ufraw Buffer Overflow

fedora
Calendar Grey June 5, 2015
Dist Fedora Esm H88
Important patch for Fedora 20 to address stack overflow in ufraw. Acquire the updated release for improved protection.
This update contains a fix for a bug which could cause dcraw write past array boundaries

Summary

UFRaw is a tool for opening raw format images of digital cameras.

Update Information:

This update contains a fix for a bug which could cause dcraw write past array boundaries.

Additionally, it updates ufraw to version 0.21, an upstream bugfix release.

Change Log

* Thu May 21 2015 Nils Philippsen - 0.21-1 - avoid writing past array boundaries when reading certain raw formats (CVE-2015-3885) * Wed May 20 2015 Nils Philippsen - 0.21-1 - version 0.21 - don't manually specify, clean buildroot - add Provides: bundled(dcraw) * Thu May 14 2015 Nils Philippsen - 0.20-4 - rebuild for lensfun-0.3.1 * Wed May 13 2015 Nils Philippsen - 0.20-3 - rebuild for lensfun-0.3.0 * Sat May 2 2015 Kalev Lember - 0.20-2 - Rebuilt for GCC 5 C++11 ABI change * Tue Oct 7 2014 Nils Philippsen - 0.20-1 - version 0.20 * Mon Aug 18 2014 Fedora Release Engineering - 0.19.2-16.20140414cvs - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Sat Aug 9 2014 Rex Dieter 0.19.2-15.20140414cvs - optimize mime scriptlet, %configure --disable-silent-rules * Sun Jun 8 2014 Fedora Release Engineering - 0.19.2-14.20140414cvs - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Tue Apr 29 2014 Nils Philippsen - 0.19.2-13 - fix tweaking color temperature, green value based off camera WB * Sat Apr 26 2014 Nils Philippsen - 0.19.2-12 - snapshot cvs20140414: fixes using camera white balance with Sony SLT-A99V * Fri Jan 10 2014 Orion Poplawski - 0.19.2-11 - Rebuild for cfitsio 3.360 * Fri Dec 6 2013 Nils Philippsen - 0.19.2-10 - harden against corrupt input files (CVE-2013-1438) * Tue Dec 3 2013 Rex Dieter 0.19.2-9 - rebuild (exiv2)

References


[ 1 ] Bug #1221249 - CVE-2015-3885 dcraw: input sanitization flaw leading to buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=1221249

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update ufraw' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ufraw
Product: Fedora 20
Version: 0.21
Release: 1.fc20
URL:
Summary: Raw image data retrieval tool for digital cameras

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here