Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Fedora 35 Advisory FEDORA-2022-e85e37206b Critical: mingw-python3 Overflow

fedora
Calendar Grey April 5, 2022
Dist Fedora Esm H88
Fedora 35 introduces an updated mingw-python3 with gdal-3.3.3 and python-3.10.4, addressing a buffer overflow issue and improving security and stability. Users should upgrade
Update to gdal-3.3.3 and python-3.10.4.

Summary

MinGW Windows python3 library.

Update to gdal-3.3.3 and python-3.10.4.

* Mon Mar 28 2022 Sandro Mani - 3.10.4-1

- Update to 3.10.4

* Fri Mar 25 2022 Sandro Mani - 3.10.3-2

- Rebuild with mingw-gcc-12

* Sun Mar 20 2022 Sandro Mani - 3.10.3-1

- Update to 3.10.3

* Mon Feb 28 2022 Sandro Mani - 3.10.2-14

- Re-add wrapper scripts under mingw host bin dir

* Sun Feb 27 2022 Sandro Mani - 3.10.2-13

- Require python%{py_ver} rather than python(abi) = %{py_ver}

* Wed Feb 23 2022 Sandro Mani - 3.10.2-12

- Rework macros

* Thu Feb 17 2022 Sandro Mani - 3.10.2-11

- Rebuild (openssl)

* Fri Feb 11 2022 Sandro Mani - 3.10.2-10

- Override runtime_library_dir_option in distutils Mingw32Compiler to prevent

unsupported -Wl,--enable-new-dtags getting added to ldflags

* Thu Feb 10 2022 Sandro Mani - 3.10.2-9

- Rebuild for new python dependency generator (take two)

* Thu Feb 10 2022 Sandro Mani - 3.10.2-8

- Bump release

* Thu Feb 10 2022 Sandro Mani - 3.10.2-7

- Add missing dependency generator namespace for provides

* Thu Feb 10 2022 Sandro Mani - 3.10.2-6

- Rebuild for new python dependency generator

* Thu Feb 10 2022 Sandro Mani - 3.10.2-5

- Install dependency generators

* Sat Jan 22 2022 Sandro Mani - 3.10.2-4

- Also set CFLAGS/CXX/CXXFLAGS/LDFLAGS in mingw-python wrappers

* Fri Jan 21 2022 Tom Stellard - 3.10.2-3

- Build fix for https://fedoraproject.org/wiki/Changes/SetBuildFlagsBuildCheck

* Thu Jan 20 2022 Fedora Release Engineering - 3.10.2-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild

* Tue Jan 18 2022 Sandro Mani - 3.10.2-1

- Update to 3.10.2

[ 1 ] Bug #2049069 - CVE-2021-45943 gdal: heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2049069

[ 2 ] Bug #2049070 - CVE-2021-45943 mingw-gdal: gdal: heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2049070

su -c 'dnf upgrade --advisory FEDORA-2022-e85e37206b' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 35
Version: 3.10.4
Release: 1.fc35
Summary: MinGW Windows python3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here