MGASA-2024-0244 - Updated python-imageio packages fix security vulnerability

Publication date: 01 Jul 2024
URL: https://advisories.mageia.org/MGASA-2024-0244.html
Type: security
Affected Mageia releases: 9

imageio can attempt to download shared freeimage libraries from
https://github.com/imageio/imageio-binaries/tree/master/freeimage. The
code fetches straight from master and provides no way of verifying
whether the correct file was fetched. As a result, if the repository is
attacked in the future, all prior versions of imageio would be silently
downloading arbitrary shared libraries and running them on user systems.
This is a serious problem.

References:
- https://bugs.mageia.org/show_bug.cgi?id=31016

SRPMS:
- 9/core/python-imageio-2.22.4-1.1.mga9

Mageia 2024-0244: python-imageio Security Advisory Updates

imageio can attempt to download shared freeimage libraries from https://github.com/imageio/imageio-binaries/tree/master/freeimage

Summary

imageio can attempt to download shared freeimage libraries from https://github.com/imageio/imageio-binaries/tree/master/freeimage. The code fetches straight from master and provides no way of verifying whether the correct file was fetched. As a result, if the repository is attacked in the future, all prior versions of imageio would be silently

References

- https://bugs.mageia.org/show_bug.cgi?id=31016

Resolution

MGASA-2024-0244 - Updated python-imageio packages fix security vulnerability

SRPMS

- 9/core/python-imageio-2.22.4-1.1.mga9

Severity
Publication date: 01 Jul 2024
URL: https://advisories.mageia.org/MGASA-2024-0244.html
Type: security

Related News