Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 22 ufraw Update FU-2015-8699 Critical: Buffer Overflow Fix

fedora
Calendar Grey June 5, 2015
Dist Fedora Esm H88
Fedora 22's GIMP package upgrade addresses critical memory safety issues and boosts graphical editing capabilities, ensuring user data protection.
This update contains a fix for a bug which could cause dcraw write past array boundaries

Summary

UFRaw is a tool for opening raw format images of digital cameras.

Update Information:

This update contains a fix for a bug which could cause dcraw write past array boundaries.

Additionally, it updates ufraw to version 0.21, an upstream bugfix release.

Change Log

* Thu May 21 2015 Nils Philippsen - 0.21-1 - avoid writing past array boundaries when reading certain raw formats (CVE-2015-3885) * Wed May 20 2015 Nils Philippsen - 0.21-1 - version 0.21 - don't manually specify, clean buildroot - add Provides: bundled(dcraw) * Thu May 14 2015 Nils Philippsen - 0.20-4 - rebuild for lensfun-0.3.1 * Wed May 13 2015 Nils Philippsen - 0.20-3 - rebuild for lensfun-0.3.0 * Sat May 2 2015 Kalev Lember - 0.20-2 - Rebuilt for GCC 5 C++11 ABI change

References


[ 1 ] Bug #1221249 - CVE-2015-3885 dcraw: input sanitization flaw leading to buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=1221249

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update ufraw' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ufraw
Product: Fedora 22
Version: 0.21
Release: 1.fc22
URL:
Summary: Raw image data retrieval tool for digital cameras

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here