Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 41: 2025-e7dea91428 moderate: mingw-LibRaw buffer access

fedora
Calendar Grey April 30, 2025
Dist Fedora Esm H88
Mingw-LibRaw version 0.21.4 now addresses out-of-bounds access vulnerabilities in Fedora 41, providing improved security measures.
Update to LibRaw 0.21.4.

Summary

MinGW Windows LibRaw library.

Update Information:

Update to LibRaw 0.21.4.

Change Log

* Wed Apr 16 2025 Sandro Mani - 0.21.4-1 - Update to 0.21.4

References


[ 1 ] Bug #2361338 - CVE-2025-43963 mingw-LibRaw: out-of-buffer access [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2361338 [ 2 ] Bug #2361343 - CVE-2025-43963 mingw-LibRaw: out-of-buffer access [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361343 [ 3 ] Bug #2361348 - CVE-2025-43963 mingw-LibRaw: out-of-buffer access [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2361348 [ 4 ] Bug #2361356 - CVE-2025-43964 mingw-LibRaw: Improper Validation of Specified Quantity in Input in LibRaw [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2361356 [ 5 ] Bug #2361361 - CVE-2025-43964 mingw-LibRaw: Improper Validation of Specified Quantity in Input in LibRaw [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361361 [ 6 ] Bug #2361366 - CVE-2025-43964 mingw-LibRaw: Improper Validation of Specified Quantity in Input in LibRaw [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2361...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e7dea91428' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: mingw-LibRaw
Product: Fedora 41
Version: 0.21.4
Release: 1.fc41
Summary: Library for reading RAW files obtained from digital photo cameras

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here