Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 37 Security Advisory: OpenImageIO 2.4.8.1 Critical Fixes

fedora
Calendar Grey February 22, 2023
Dist Fedora Esm H88
Fedora's latest update for OpenImageIO, version 2.4.8.1, resolves critical bugs and boosts stability, ensuring improved performance for all users
Release 2.4.8.1 (13 Feb 2023) -- compared to 2.4.8.0 * Fix(targa): guard against corrupted tga files Fixes TALOS-2023-1707 / CVE-2023-24473, TALOS-2023-1708 / CVE-2023-22845

Summary

OpenImageIO is a library for reading and writing images, and a bunch of related

classes, utilities, and applications. Main features include:

- Extremely simple but powerful ImageInput and ImageOutput APIs for reading and

writing 2D images that is format agnostic.

- Format plugins for TIFF, JPEG/JFIF, OpenEXR, PNG, HDR/RGBE, Targa, JPEG-2000,

DPX, Cineon, FITS, BMP, ICO, RMan Zfile, Softimage PIC, DDS, SGI,

PNM/PPM/PGM/PBM.

- An ImageCache class that transparently manages a cache so that it can access

truly vast amounts of image data.

Release 2.4.8.1 (13 Feb 2023) -- compared to 2.4.8.0 * Fix(targa): guard

against corrupted tga files Fixes TALOS-2023-1707 / CVE-2023-24473,

TALOS-2023-1708 / CVE-2023-22845. #3768 * Fix: race condition in TIFF reader,

fixes TALOS-2023-1709 / CVE-2023-24472. * Windows: Fix unresolved external

symbol for MSVS 2017 #3763 * Fix: Initialize OpenEXROutput::m_levelmode in

init(). #3764 * Fix: improve thread safety for concurrent tiff loads. #3767 *

Fix(fits): Make sure to close if open fails to find right magic number.

* Tue Feb 14 2023 Richard Shaw - 2.4.8.1-1

- Update to 2.4.8.1.

su -c 'dnf upgrade --advisory FEDORA-2023-c3d65c8f7b' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 37
Version: 2.4.8.1
Release: 1.fc37
Summary: Library for reading and writing images

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here