Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 33: 2021-0610b49277 Critical: stb Buffer Overflow and DoS Risk

fedora
Calendar Grey October 30, 2021
Dist Fedora Esm H88
Essential security patch for Fedora 33 mitigating buffer overflow vulnerabilities and DoS risks in stb libraries.
Security fix for CVE-2021-42715 and CVE-2021-42716

Summary

Single-file public domain libraries for C/C++.

Security fix for CVE-2021-42715 and CVE-2021-42716

* Fri Oct 22 2021 Benjamin A. Beasley 0-0.7

- Security fix for CVE-2021-42715 and CVE-2021-42716

* Fri Oct 22 2021 Benjamin A. Beasley 0-0.6

- Update to af1a5bc

* Fri Oct 22 2021 Benjamin A. Beasley 0-0.5

- Reduce macro indirection in the spec file

[ 1 ] Bug #2017908 - CVE-2021-42715 stb: DoS in stb_image HDR loader via a crafted file

https://bugzilla.redhat.com/show_bug.cgi?id=2017908

[ 2 ] Bug #2017913 - CVE-2021-42716 stb: heap-based buffer overflow in stb_image PNM loader

https://bugzilla.redhat.com/show_bug.cgi?id=2017913

su -c 'dnf upgrade --advisory FEDORA-2021-0511a38484' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 33
Version: 0
Release: 0.7.20211022gitaf1a5bc.fc33
Summary: Single-file public domain libraries for C/C++

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here