Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 22: Update 2015-8432 Critical: LibRaw Input Sanitization Flaw

fedora
Calendar Grey May 26, 2015
Dist Fedora Esm H88
The latest LibRaw update for Fedora 22 addresses the dcraw security flaw, enhancing overall system stability. Key improvements have been outlined.
Latest upstream bugfix

Summary

LibRaw is a library for reading RAW files obtained from digital photo

cameras (CRW/CR2, NEF, RAF, DNG, and others).

LibRaw is based on the source codes of the dcraw utility, where part of

drawbacks have already been eliminated and part will be fixed in future.

Update Information:

Latest upstream bugfix. Fixed dcraw vulnerability in ljpeg_start()

Change Log

* Sat May 16 2015 Jon Ciesla - 0.16.2-1 - 0.16.2, BZ 1222258. * Thu May 14 2015 Jon Ciesla - 0.16.1-7 - Add provides for bundled dcraw, https://pagure.io/packaging-committee/issue/530 - Fix EVR in changelog.

References


[ 1 ] Bug #1222258 - LibRaw-0.16.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1222258 [ 2 ] Bug #1220382 - LibRaw-0.16.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1220382 [ 3 ] Bug #1221250 - CVE-2015-3885 LibRaw: dcraw: input sanitization flaw leading to buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1221250

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update LibRaw' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: LibRaw
Product: Fedora 22
Version: 0.16.2
Release: 1.fc22
Summary: Library for reading RAW files obtained from digital photo cameras

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here