Alerts This Week
Warning Icon 1 770
Alerts This Week
Warning Icon 1 770

openSUSE: 2024:0786-1 Important Threats in Giflib Update

opensuse
Calendar Grey March 7, 2024
Dist Opensuse Esm H88
Urgent security notice regarding giflib vulnerabilities impacting various SUSE offerings, with crucial updates available to mitigate these threats.
This update for giflib fixes the following issues: Update to version 5.2.2

Description

This update for giflib fixes the following issues:

Update to version 5.2.2

* Fixes for CVE-2023-48161 (bsc#1217390), CVE-2022-28506 (bsc#1198880)

* # 138 Documentation for obsolete utilities still installed

* # 139: Typo in "LZW image data" page ("110_2 = 4_10")

* # 140: Typo in "LZW image data" page ("LWZ")

* # 141: Typo in "Bits and bytes" page ("filed")

* Note as already fixed SF issue #143: cannot compile under mingw

* # 144: giflib-5.2.1 cannot be build on windows and other platforms using c89

* # 145: Remove manual pages installation for binaries that are not installed

too

* # 146: [PATCH] Limit installed man pages to binaries, move giflib to section

7

* # 147 [PATCH] Fixes to doc/whatsinagif/ content

* # 148: heap Out of Bound Read in gif2rgb.c:298 DumpScreen2RGB

* Declared no-info on SF issue #150: There is a denial of service

vulnerability in GIFLIB 5.2.1

* Declared Won't-fix on SF issue 149: Out of source builds no longer...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2024-786=1

* Basesystem Module 15-SP5

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-786=1

* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2

zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-786=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3

zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-786=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-786=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-786=1

* SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4

zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-786=1

* SUSE Linux Enterprise...

Read the Full Advisory

Package List

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)

* giflib-debugsource-5.2.2-150000.4.13.1

* libgif7-debuginfo-5.2.2-150000.4.13.1

* libgif7-5.2.2-150000.4.13.1

* giflib-progs-5.2.2-150000.4.13.1

* giflib-progs-debuginfo-5.2.2-150000.4.13.1

* giflib-devel-5.2.2-150000.4.13.1

* openSUSE Leap 15.5 (x86_64)

* libgif7-32bit-5.2.2-150000.4.13.1

* giflib-devel-32bit-5.2.2-150000.4.13.1

* libgif7-32bit-debuginfo-5.2.2-150000.4.13.1

* Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64)

* libgif7-5.2.2-150000.4.13.1

* giflib-debugsource-5.2.2-150000.4.13.1

* libgif7-debuginfo-5.2.2-150000.4.13.1

* giflib-devel-5.2.2-150000.4.13.1

* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64

x86_64)

* libgif7-5.2.2-150000.4.13.1

* giflib-debugsource-5.2.2-150000.4.13.1

* libgif7-debuginfo-5.2.2-150000.4.13.1

* giflib-devel-5.2.2-150000.4.13.1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64

x86_64)

* libgif7-5.2.2-150000.4.13.1

* giflib-debugsource-5.2.2-150000.4.13.1

*...

Read the Full Advisory

References

* bsc#1198880

* bsc#1200551

* bsc#1217390

## References:

* https://www.suse.com/security/cve/CVE-2021-40633.html

* https://www.suse.com/security/cve/CVE-2022-28506.html

* https://www.suse.com/security/cve/CVE-2023-48161.html

* https://bugzilla.suse.com/show_bug.cgi?id=1198880

* https://bugzilla.suse.com/show_bug.cgi?id=1200551

* https://bugzilla.suse.com/show_bug.cgi?id=1217390

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:0786-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here