Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 31: FEDORA-2019-655994894e Critical: FreeImage Buffer Overflow

fedora
Calendar Grey November 26, 2019
Dist Fedora Esm H88
Implement security patches for FreeImage in Fedora 31 to ensure your system remains current and protected with the newest updates.
Backport fixes for CVE-2019-12211 and 2019-12213

Summary

FreeImage is a library for developers who would like to support popular

graphics image formats like PNG, BMP, JPEG, TIFF and others as needed by

today's multimedia applications.

Backport fixes for CVE-2019-12211 and 2019-12213

* Sun Nov 17 2019 Sandro Mani - 3.18.0-6

- Backport fixes for CVE-2019-12211 and 2019-12213

[ 1 ] Bug #1732246 - CVE-2019-12211 freeimage: heap-based buffer overflow in PluginTIFF.cpp [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1732246

[ 2 ] Bug #1732232 - CVE-2019-12213 freeimage: stack exhaustion in function TIFFReadDirectory in PluginTIFF.cpp [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1732232

[ 3 ] Bug #1732247 - CVE-2019-12211 mingw-freeimage: freeimage: heap-based buffer overflow in PluginTIFF.cpp [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1732247

[ 4 ] Bug #1732233 - CVE-2019-12213 mingw-freeimage: freeimage: stack exhaustion in function TIFFReadDirectory in PluginTIFF.cpp [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1732233

su -c 'dnf upgrade --advisory FEDORA-2019-655994894e' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 31
Version: 3.18.0
Release: 6.fc31
Summary: Multi-format image decoder library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here