Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 39: libgsf 2024-7d06f67cf5 Security Advisory Updates

fedora
Calendar Grey October 14, 2024
Dist Fedora Esm H88
Fixes for memory vulnerabilities in libgsf for Fedora 39, addressing critical issues that could affect system functionality.
Fixes for memory vulnerabilities.

Summary

A library for reading and writing structured files (e.g. MS OLE and Zip)

Update Information:

Fixes for memory vulnerabilities.

Change Log

* Fri Oct 11 2024 Gwyn Ciesla - 1.14.53-1 - 1.14.53 * Thu Jul 18 2024 Fedora Release Engineering - 1.14.52-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild * Fri May 31 2024 Gwyn Ciesla - 1.14.52-1 - 1.14.52 * Thu Jan 25 2024 Fedora Release Engineering - 1.14.51-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering - 1.14.51-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Thu Nov 30 2023 David King - 1.14.51-2 - Fix building against libxml 2.12.0 - Use pkgconfig for BuildRequires

References


[ 1 ] Bug #2317953 - (CVE-2024-42415) - CVE-2024-42415 libgsf: Compound Document Binary File Sector Allocation Table integer overflow vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2317953 [ 2 ] Bug #2317954 - (CVE-2024-36474) - CVE-2024-36474 libgsf: Compound Document Binary File Directory integer overflow vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2317954

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-7d06f67cf5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libgsf
Product: Fedora 39
Version: 1.14.53
Release: 1.fc39
URL:
Summary: GNOME Structured File library

Topics%20covered

Topics Covered

No topics assigned

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here