An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for chafa ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10045-1 Rating: moderate References: #1201211 Cross-References: CVE-2022-2301 Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for chafa fixes the following issues: - CVE-2022-2301: Fixed buffer over-read (boo#1201211) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10045=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): chafa-1.8.0-bp154.3.8.1 chafa-debuginfo-1.8.0-bp154.3.8.1 chafa-debugsource-1.8.0-bp154.3.8.1 chafa-devel-1.8.0-bp154.3.8.1 libchafa0-1.8.0-bp154.3.8.1 libchafa0-debuginfo-1.8.0-bp154.3.8.1 - openSUSE Backports SLE-15-SP4 (noarch): chafa-doc-1.8.0-bp154.3.8.1 References: https://www.suse.com/security/cve/CVE-2022-2301.html https://bugzilla.suse.com/1201211 . Addresses a medium severity buffer over-read flaw in chafa for openSUSE users and includes guidance for applying updates.. openSUSE Update, Buffer Over-Read Fix, Chafa Security Patch. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for chafa ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10044-1 Rating: moderate References: #1201211 Cross-References: CVE-2022-2301 Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for chafa fixes the following issues: - CVE-2022-2301: Fix buffer over-read (boo#1201211) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-10044=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): chafa-1.4.1-bp153.2.8.1 chafa-debuginfo-1.4.1-bp153.2.8.1 chafa-debugsource-1.4.1-bp153.2.8.1 chafa-devel-1.4.1-bp153.2.8.1 libchafa0-1.4.1-bp153.2.8.1 libchafa0-debuginfo-1.4.1-bp153.2.8.1 - openSUSE Backports SLE-15-SP3 (noarch): chafa-doc-1.4.1-bp153.2.8.1 References: https://www.suse.com/security/cve/CVE-2022-2301.html https://bugzilla.suse.com/1201211 . Recent security patch for openSUSE addresses a significant buffer overflow vulnerability cataloged as CVE-2022-2302.. openSUSE Security Update,chafa buffer over-read,security update openSUSE. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for chafa ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10025-1 Rating: moderate References: #1198965 Cross-References: CVE-2022-1507 CVSS scores: CVE-2022-1507 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for chafa fixes the following issues: - CVE-2022-1507: Fix NULL pointer deref in gif_internal_decode_frame (boo#1198965) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-10025=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): chafa-1.4.1-bp153.2.3.1 chafa-devel-1.4.1-bp153.2.3.1 libchafa0-1.4.1-bp153.2.3.1 - openSUSE Backports SLE-15-SP3 (noarch): chafa-doc-1.4.1-bp153.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-1507.html https://bugzilla.suse.com/1198965 . A critical performance enhancement for flutter on Fedora tackles significant vulnerabilities efficiently, accompanied by setup guidelines.. openSUSE Security Update,chafa fix,moderate risk,security measures. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for chafa ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10017-1 Rating: important References: #1200510 Cross-References: CVE-2022-2061 Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for chafa fixes the following issues: - CVE-2022-2061: Fix heap based buffer overflow in lzw_decode (boo#1200510) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10017=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): chafa-1.8.0-bp154.3.3.1 chafa-devel-1.8.0-bp154.3.3.1 libchafa0-1.8.0-bp154.3.3.1 - openSUSE Backports SLE-15-SP4 (noarch): chafa-doc-1.8.0-bp154.3.3.1 References: https://www.suse.com/security/cve/CVE-2022-2061.html https://bugzilla.suse.com/1200510 . Important security patch for chafa resolves a buffer overflow vulnerability impacting openSUSE Backports SLE-15-SP4.. openSUSE Security Update, chafa vulnerability, buffer overflow patch. . Severity: Important. LinuxSecurity.com Team
ImageMagick is updated 6.9.12-31 , soname bump , many security fixes. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-b58af96f33 2021-12-05 01:37:20.956040 --------------------------------------------------------------------------------Name : chafa Product : Fedora 34 Version : 1.2.1 Release : 6.fc34 URL : https://hpjansson.org/chafa/ Summary : Image-to-text converter for terminal Description : Chafa is a command-line utility that converts all kinds of images, including animated image formats like GIFs, into ANSI/Unicode character output that can be displayed in a terminal. It is highly configurable, with support for alpha transparency and multiple color modes and color spaces, combining a range of Unicode characters for optimal output. --------------------------------------------------------------------------------Update Information: ImageMagick is updated 6.9.12-31 , soname bump , many security fixes --------------------------------------------------------------------------------ChangeLog: * Wed Nov 3 2021 Mamoru TASAKA - 1.2.1-6 - rebuild for new ImageMagick * Wed Jul 21 2021 Fedora Release Engineering - 1.2.1-5 - Rebuilt for --------------------------------------------------------------------------------References: [ 1 ] Bug #1901226 - CVE-2020-25664 ImageMagick: heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1901226 [ 2 ] Bug #2025909 - ImageMagick-6.9.12-31 is available https://bugzilla.redhat.com/show_bug.cgi?id=2025909 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-b58af96f33' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.