Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 42: OpenImageIO 2025-22c8d5a1c7 Security Advisory Updates

fedora
Calendar Grey March 15, 2025
Dist Fedora Esm H88
This advisory details critical security patches for OpenImageIO addressing CVE-2024-27628 and CVE-2024-28130 vulnerabilities.
Update for dcmtk 3.6.9 Includes security fix for CVE-2024-27628, CVE-2024-28130

Summary

OpenImageIO is a library for reading and writing images, and a bunch of related

classes, utilities, and applications. Main features include:

- Extremely simple but powerful ImageInput and ImageOutput APIs for reading and

writing 2D images that is format agnostic.

- Format plugins for TIFF, JPEG/JFIF, OpenEXR, PNG, HDR/RGBE, Targa, JPEG-2000,

DPX, Cineon, FITS, BMP, ICO, RMan Zfile, Softimage PIC, DDS, SGI,

PNM/PPM/PGM/PBM.

- An ImageCache class that transparently manages a cache so that it can access

truly vast amounts of image data.

Update Information:

Update for dcmtk 3.6.9 Includes security fix for CVE-2024-27628, CVE-2024-28130

Change Log

* Mon Feb 24 2025 Ankur Sinha - 2.5.16.0-6 - Rebuild for dcmtk 3.6.9

References


[ 1 ] Bug #2293952 - CVE-2024-28130 dcmtk: incorrect type conversion https://bugzilla.redhat.com/show_bug.cgi?id=2293952 [ 2 ] Bug #2294757 - CVE-2024-27628 dcmtk: Buffer Overflow via the EctEnhancedCT method https://bugzilla.redhat.com/show_bug.cgi?id=2294757

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-22c8d5a1c7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: OpenImageIO
Product: Fedora 42
Version: 2.5.16.0
Release: 6.fc42
Summary: Library for reading and writing images

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here