Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 33: 2020-2d9d628dd2 Critical: LibRaw Null Pointer Issue

fedora
Calendar Grey September 25, 2020
Dist Fedora Esm H88
This announcement pertains to a crucial update for LibRaw aimed at resolving significant vulnerabilities within Fedora environments.
Patch for CVE-2020-24890

Summary

LibRaw is a library for reading RAW files obtained from digital photo

cameras (CRW/CR2, NEF, RAF, DNG, and others).

LibRaw is based on the source codes of the dcraw utility, where part of

drawbacks have already been eliminated and part will be fixed in future.

Patch for CVE-2020-24890

* Thu Sep 24 2020 Gwyn Ciesla - 0.20.0-3

- Patch for CVE-2020-24890.

[ 1 ] Bug #1882345 - CVE-2020-24890 LibRaw: null pointer dereference in parse_tiff_ifd in src/metadata/tiff.cpp [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1882345

[ 2 ] Bug #1882349 - CVE-2020-24890 LibRaw: null pointer dereference in parse_tiff_ifd in src/metadata/tiff.cpp [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1882349

su -c 'dnf upgrade --advisory FEDORA-2020-2d9d628dd2' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 33
Version: 0.20.0
Release: 3.fc33
Summary: Library for reading RAW files obtained from digital photo cameras

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here