libheif could be made to crash if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-6847-1 June 25, 2024 libheif vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: libheif could be made to crash if it opened a specially crafted file. Software Description: - libheif: ISO/IEC 23008-12:2017 HEIF file format decoder - development file Details: It was discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-11471) Reza Mirzazade Farkhani discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-23109) Eugene Lim discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-0996) Min Jang discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-29659) Yuchuan Meng discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. This issue only affected Ubuntu 23.10. (CVE-2023-49460, CVE-2023-49462, CVE-2023-49463, CVE-2023-49464) Update instructions: The problem can be corrected by updating your system to thefollowing package versions: Ubuntu 23.10 heif-gdk-pixbuf 1.16.2-2ubuntu1.1 libheif-dev 1.16.2-2ubuntu1.1 libheif-plugin-libde265 1.16.2-2ubuntu1.1 libheif1 1.16.2-2ubuntu1.1 Ubuntu 22.04 LTS heif-gdk-pixbuf 1.12.0-2ubuntu0.1~esm1 Available with Ubuntu Pro libheif-dev 1.12.0-2ubuntu0.1~esm1 Available with Ubuntu Pro libheif1 1.12.0-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS heif-gdk-pixbuf 1.6.1-1ubuntu0.1~esm1 Available with Ubuntu Pro libheif-dev 1.6.1-1ubuntu0.1~esm1 Available with Ubuntu Pro libheif1 1.6.1-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libheif-dev 1.1.0-2ubuntu0.1~esm1 Available with Ubuntu Pro libheif1 1.1.0-2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6847-1 CVE-2019-11471, CVE-2020-23109, CVE-2023-0996, CVE-2023-29659, CVE-2023-49460, CVE-2023-49462, CVE-2023-49463, CVE-2023-49464 Package Information: https://launchpad.net/ubuntu/+source/libheif/1.16.2-2ubuntu1.1 . Ubuntu Security Advisory USN-6847-1 highlights vulnerabilities associated with libheif impacting multiple versions and offers guidance for updates.. libheif update, Ubuntu security, denial of service, image handling errors, libheif vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Fix CVE-2018-19655. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-ef1ff20b59 2020-03-29 00:14:52.079997 --------------------------------------------------------------------------------Name : dcraw Product : Fedora 32 Version : 9.28.0 Release : 9.fc32 URL : http://www.dechifro.org/dcraw/ Summary : Tool for decoding raw image data from digital cameras Description : This package contains dcraw, a command line tool to decode raw image data downloaded from digital cameras. --------------------------------------------------------------------------------Update Information: Fix CVE-2018-19655 --------------------------------------------------------------------------------ChangeLog: * Fri Mar 20 2020 Josef Ridky - 9.28.0-9 - Fix CVE-2018-19655 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-ef1ff20b59' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.