Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Fedora 39: 2023-a0d9f1d7ae Urgent Patch for Libjpeg-Turbo Buffer Underflow

fedora
Calendar Grey September 7, 2023
Dist Fedora Esm H88
Upgrade tinyexr on Fedora 38 to fix heap overflow issue found in CVE-2022-34300. Immediate action recommended.
Upstream patch to fix CVE-2022-34300 Fixes rhbz#2233636

Summary

TinyEXR is a small library to load and save OpenEXR images. It supports

the version 1 format and version 2 multi-part images, and it has partial

support for version 2 deep images.

Update Information:

Upstream patch to fix CVE-2022-34300 Fixes rhbz#2233636

Change Log

* Tue Aug 29 2023 Diego Herrera - 1.0.1-7 - Patch to fix CVE-2022-34300 * Sat Jul 22 2023 Fedora Release Engineering - 1.0.1-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild

References


[ 1 ] Bug #2233636 - CVE-2022-34300 tinyexr: heap-based buffer over-read in tinyexr::DecodePixelData [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2233636

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-3e092b3938' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
important
Lowest
Low
Medium
High
Critical

Name: tinyexr
Product: Fedora 38
Version: 1.0.1
Release: 7.fc38
Summary: Small library to load and save OpenEXR images

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here