Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora: FEDORA-2020-5d0f0593ae moderate: transfig Out-of-Bounds Issue

fedora
Calendar Grey January 25, 2020
Dist Fedora Esm H88
Fedora has issued a security notice about the transfig utility, focusing on vulnerabilities related to CVE incidents involving out-of-bounds reads and integer overflow exploits
- Security fix for CVE-2019-19746, CVE-2019-19797 - New upstream release 3.2.7b - Add patch fixing CVE-2019-19746 (rhbz#1787040) - Add patch fixing CVE-2019-19797 (rhbz#1786726)

Summary

The transfig utility creates a makefile which translates FIG (created

by xfig) or PIC figures into a specified LaTeX graphics language (for

example, PostScript(TM)). Transfig is used to create TeX documents

which are portable (i.e., they can be printed in a wide variety of

environments).

Install transfig if you need a utility for translating FIG or PIC

figures into certain graphics languages.

- Security fix for CVE-2019-19746, CVE-2019-19797 - New upstream release 3.2.7b

- Add patch fixing CVE-2019-19746 (rhbz#1787040) - Add patch fixing

CVE-2019-19797 (rhbz#1786726)

* Wed Jan 15 2020 Hans de Goede - 1:3.2.7b-1

- New upstream release 3.2.7b

- Add patch fixing CVE-2019-19746 (rhbz#1787040)

- Add patch fixing CVE-2019-19797 (rhbz#1786726)

[ 1 ] Bug #1786726 - CVE-2019-19797 transfig: out-of-bounds write in read_colordef in read.c

https://bugzilla.redhat.com/show_bug.cgi?id=1786726

[ 2 ] Bug #1787040 - CVE-2019-19746 transfig: integer overflow leads to out-of-bounds write in make_arrow in arrow.c

https://bugzilla.redhat.com/show_bug.cgi?id=1787040

su -c 'dnf upgrade --advisory FEDORA-2020-5d0f0593ae' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 31
Version: 3.2.7b
Release: 1.fc31
Summary: Utility for converting FIG files (made by xfig) to other formats

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here