Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 39: FEDORA-2024-c0b61ab46b Urgent: FreeImage Buffer Overflow Fix

fedora
Calendar Grey March 19, 2024
Dist Fedora Esm H88
Incorporate required adjustments in FreeImage for Fedora to rectify buffer overflow vulnerabilities and eliminate instances of infinite loops.
Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Summary

FreeImage is a library for developers who would like to support popular

graphics image formats like PNG, BMP, JPEG, TIFF and others as needed by

today's multimedia applications.

Update Information:

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Change Log

* Sun Mar 10 2024 Sandro Mani - 3.19.0-0.23.svn1909 - Add downstream patches for CVE-2023-47997, CVE-2023-47995 * Wed Jan 24 2024 Fedora Release Engineering - 3.19.0-0.22.svn1909 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Fedora Release Engineering - 3.19.0-0.21.svn1909 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

References


[ 1 ] Bug #2257661 - CVE-2023-47995 freeimage: Buffer Overflow vulnerability in FreeImage_AllocateBitmap [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257661 [ 2 ] Bug #2257665 - CVE-2023-47997 freeimage: infinite loop exits in Load in PluginTIFF.cpp [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257665 [ 3 ] Bug #2257666 - CVE-2023-47995 mingw-freeimage: FreeImage: Buffer Overflow vulnerability in FreeImage_AllocateBitmap [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257666 [ 4 ] Bug #2257670 - CVE-2023-47997 mingw-freeimage: FreeImage: infinite loop exits in Load in PluginTIFF.cpp [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257670

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c0b61ab46b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: freeimage
Product: Fedora 39
Version: 3.19.0
Release: 0.23.svn1909.fc39
Summary: Multi-format image decoder library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here