Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 25 Potrace Security Update - Critical Buffer Overflow Fixed

fedora
Calendar Grey August 15, 2017
Dist Fedora Esm H88
The new Potrace release for Fedora 25 brings essential security upgrades addressing buffer and arithmetic overflow flaws, improving system compatibility and fixing bugs
This release consists of bugfixes and minor portability improvements

Summary

Potrace is a utility for tracing a bitmap, which means, transforming a bitmap

into a smooth, scalable image. The input is a bitmap (PBM, PGM, PPM, or BMP

format), and the default output is an encapsulated PostScript file (EPS).

A typical use is to create EPS files from scanned data, such as company or

university logos, handwritten notes, etc. The resulting image is not "jaggy"

like a bitmap, but smooth. It can then be rendered at any resolution.

Potrace can currently produce the following output formats: EPS, PostScript,

PDF, SVG (scalable vector graphics), Xfig, Gimppath, and PGM (for easy

antialiasing). Additional backends might be added in the future.

Mkbitmap is a program distributed with Potrace which can be used to pre-process

the input for better tracing behavior on greyscale and color images.

This release consists of bugfixes and minor portability improvements. Some

potential buffer overflows and arithmetic overflows were fixed, including

CVE-2017-12067. A bug triggered by very large bitmaps has been fixed.

[ 1 ] Bug #1477104 - CVE-2017-12067 potrace: heap-based buffer over-read in the interpolate_cubic function [epel-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1477104

[ 2 ] Bug #1385513 - CVE-2016-8685 CVE-2016-8686 CVE-2016-8694 CVE-2016-8695 CVE-2016-8696 CVE-2016-8697 CVE-2016-8698 CVE-2016-8699 CVE-2016-8700 CVE-2016-8701 CVE-2016-8702 CVE-2016-8703 CVE-2017-7263 potrace: Multiple security issues [epel-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1385513

[ 3 ] Bug #1477105 - CVE-2017-12067 potrace: heap-based buffer over-read in the interpolate_cubic function [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1477105

[ 4 ] Bug #1385512 - CVE-2016-8685 CVE-2016-8686 CVE-2016-8694 CVE-2016-8695 CVE-2016-8696 CVE-2016-8697 CVE-2016-8698 CVE-2016-8699 CVE-2016-8700 CVE-2016-8701 CVE-2016-8702 CVE-2016-8703 CVE-2017-7263 potrace: Multiple security issues [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1385512

su -c 'dnf upgrade potrace' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 25
Version: 1.15
Release: 1.fc25
URL:
Summary: Transform bitmaps into vector graphics

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here