Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Fedora 38: 2024-e6a35cd250 Moderate: FreeImage Buffer Overflow Advisory

fedora
Calendar Grey March 19, 2024
Scroller Fedora
Implement corrective measures to address memory overflow vulnerabilities and infinite loop scenarios in Fedora's FreeImage library as per this security advisory.
Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Summary

FreeImage is a library for developers who would like to support popular

graphics image formats like PNG, BMP, JPEG, TIFF and others as needed by

today's multimedia applications.

Update Information:

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Change Log

* Sun Mar 10 2024 Sandro Mani - 3.19.0-0.23.svn1909 - Add downstream patches for CVE-2023-47997, CVE-2023-47995 * Wed Jan 24 2024 Fedora Release Engineering - 3.19.0-0.22.svn1909 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Fedora Release Engineering - 3.19.0-0.21.svn1909 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

References


[ 1 ] Bug #2257661 - CVE-2023-47995 freeimage: Buffer Overflow vulnerability in FreeImage_AllocateBitmap [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257661 [ 2 ] Bug #2257665 - CVE-2023-47997 freeimage: infinite loop exits in Load in PluginTIFF.cpp [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257665 [ 3 ] Bug #2257666 - CVE-2023-47995 mingw-freeimage: FreeImage: Buffer Overflow vulnerability in FreeImage_AllocateBitmap [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257666 [ 4 ] Bug #2257670 - CVE-2023-47997 mingw-freeimage: FreeImage: infinite loop exits in Load in PluginTIFF.cpp [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257670

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-e6a35cd250' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
important
Lowest
Low
Medium
High
Critical

Name: freeimage
Product: Fedora 38
Version: 3.19.0
Release: 0.23.svn1909.fc38
Summary: Multi-format image decoder library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.