Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 9: MSAG-2024-0244 Moderate: Python-Imageio Download Risk

mageia
Calendar Grey July 1, 2024
Dist Mageia Esm H88
The latest python-imageio updates resolve a major security vulnerability in Mageia. Enhancements included thwart possible library exploitation.
imageio can attempt to download shared freeimage libraries from https://github.com/imageio/imageio-binaries/tree/master/freeimage

Summary

imageio can attempt to download shared freeimage libraries from https://github.com/imageio/imageio-binaries/tree/master/freeimage. The code fetches straight from master and provides no way of verifying whether the correct file was fetched. As a result, if the repository is attacked in the future, all prior versions of imageio would be silently

References

- https://bugs.mageia.org/show_bug.cgi?id=31016

Resolution

SRPMS

- 9/core/python-imageio-2.22.4-1.1.mga9

Publication date: 01 Jul 2024
URL: https://advisories.mageia.org/MGASA-2024-0244.html
Type: security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here