Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 30 xfig Security Advisory: FEDORA-2020-6a2824178e Moderate Threat

fedora
Calendar Grey January 24, 2020
Dist Fedora Esm H88
An update for Fedora 30 resolves security vulnerabilities in gimp, correcting issues related to buffer overflow and null pointer dereference.
- Security fix for CVE-2019-19746, CVE-2019-19797 - New upstream release 3.2.7b - Add patch fixing CVE-2019-19746 (rhbz#1787040) - Add patch fixing CVE-2019-19797 (rhbz#1786726)

Summary

Xfig is an X Window System tool for creating basic vector graphics,

including bezier curves, lines, rulers and more. The resulting

graphics can be saved, printed on PostScript printers or converted to

a variety of other formats (e.g., X11 bitmaps, Encapsulated

PostScript, LaTeX).

You should install xfig if you need a simple program to create vector

graphics.

- Security fix for CVE-2019-19746, CVE-2019-19797 - New upstream release 3.2.7b

- Add patch fixing CVE-2019-19746 (rhbz#1787040) - Add patch fixing

CVE-2019-19797 (rhbz#1786726)

* Thu Jan 16 2020 Hans de Goede - 3.2.7b-1

- New upstream release 3.2.7b

* Sat Jul 27 2019 Fedora Release Engineering - 3.2.7a-4

- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild

[ 1 ] Bug #1786726 - CVE-2019-19797 transfig: out-of-bounds write in read_colordef in read.c

https://bugzilla.redhat.com/show_bug.cgi?id=1786726

[ 2 ] Bug #1787040 - CVE-2019-19746 transfig: integer overflow leads to out-of-bounds write in make_arrow in arrow.c

https://bugzilla.redhat.com/show_bug.cgi?id=1787040

su -c 'dnf upgrade --advisory FEDORA-2020-6a2824178e' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 30
Version: 3.2.7b
Release: 1.fc30
Summary: An X Window System tool for drawing basic vector graphics

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here