It was discovered that there were two issues in libheif, a decoder and encoder for the HEIF and AVIF image formats that could have been exploited by specially-crafted image files. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3945-1
Backport proposed fix for CVE-2021-33367.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-748f1d5710 2023-04-22 00:53:57.594958 --------------------------------------------------------------------------------Name : freeimage Product : Fedora 37 Version : 3.19.0 Release : 0.16.svn1889.fc37 URL : https://freeimage.sourceforge.io/ Summary : Multi-format image decoder library Description : FreeImage is a library for developers who would like to support popular graphics image formats like PNG, BMP, JPEG, TIFF and others as needed by today's multimedia applications. --------------------------------------------------------------------------------Update Information: Backport proposed fix for CVE-2021-33367. --------------------------------------------------------------------------------ChangeLog: * Thu Apr 13 2023 Sandro Mani - 3.19.0-0.16.svn1889 - Fix empty CVE-2021-33367.patch * Thu Apr 13 2023 Sandro Mani - 3.19.0-0.15.svn1889 - Add proposed fix for CVE-2021-33367 * Thu Apr 6 2023 Sandro Mani - 3.19.0-0.14.svn1889 - Syncronize FreeImage_unbundle.patch with mingw-freeimage * Thu Jan 19 2023 Fedora Release Engineering - 3.19.0-0.13.svn1889 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Tue Dec 20 2022 Gwyn Ciesla - 3.19.0-0.12.svn1889 - LibRaw rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2172783 - CVE-2021-33367 freeimage: denial of service via a crafted JXR file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2172783 [ 2 ] Bug #2172785 - CVE-2021-33367 mingw-freeimage: Freeimage: denial of service via a crafted JXR file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2172785 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2023-748f1d5710' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
rebase to 0.16 (bz #1741605). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-55973f4ef8 2019-09-16 02:20:42.426776 --------------------------------------------------------------------------------Name : jbig2dec Product : Fedora 29 Version : 0.16 Release : 1.fc29 URL : https://sourceforge.net/projects/jbig2dec/ Summary : A decoder implementation of the JBIG2 image compression format Description : jbig2dec is a decoder implementation of the JBIG2 image compression format. JBIG2 is designed for lossy or lossless encoding of 'bilevel' (1-bit monochrome) images at moderately high resolution, and in particular scanned paper documents. In this domain it is very efficient, offering compression ratios on the order of 100:1. --------------------------------------------------------------------------------Update Information: rebase to 0.16 (bz #1741605) --------------------------------------------------------------------------------ChangeLog: * Thu Aug 15 2019 Michael J Gruber - 0.16-1 - rebase to 0.16 (bz #1741605) * Thu Jul 25 2019 Fedora Release Engineering - 0.14-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Fri Feb 1 2019 Fedora Release Engineering - 0.14-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Tue Sep 18 2018 Owen Taylor - 0.14-4 - Handle both compressed and uncompressed man pages --------------------------------------------------------------------------------References: [ 1 ] Bug #1741605 - jbig2dec needs to be rebased to 0.16 (currently 0.14) for ghostscript rebase to 9.27 https://bugzilla.redhat.com/show_bug.cgi?id=1741605 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-55973f4ef8' at the command line. For more information, refer to the dnf documentationavailable at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
update to 0.14 (bugfix release CVE-2017-9216). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-ed565f9ed0 2017-11-28 16:32:27.213055 --------------------------------------------------------------------------------Name : jbig2dec Product : Fedora 25 Version : 0.14 Release : 1.fc25 URL : https://sourceforge.net/projects/jbig2dec/ Summary : A decoder implementation of the JBIG2 image compression format Description : jbig2dec is a decoder implementation of the JBIG2 image compression format. JBIG2 is designed for lossy or lossless encoding of 'bilevel' (1-bit monochrome) images at moderately high resolution, and in particular scanned paper documents. In this domain it is very efficient, offering compression ratios on the order of 100:1. --------------------------------------------------------------------------------Update Information: update to 0.14 (bugfix release CVE-2017-9216) --------------------------------------------------------------------------------References: [ 1 ] Bug #1456730 - CVE-2017-9216 jbig2dec: Null pointer dereference in jbig2_huffman_get() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1456730 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade jbig2dec' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Several vulnerabilities.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-289 2004-09-15 --------------------------------------------------------------------- Product : Fedora Core 2 Name : gtk2 Version : 2.4.7 Release : 2.4 Summary : The GIMP ToolKit (GTK+), a library for creating GUIs for X. Description : GTK+ is a multi-platform toolkit for creating graphical user interfaces. Offering a complete set of widgets, GTK+ is suitable for projects ranging from small one-off tools to complete application suites. --------------------------------------------------------------------- Update Information: During testing of a previously fixed flaw in Qt (CAN-2004-0691), a flaw was discovered in the BMP image processor of gtk2. An attacker could create a carefully crafted BMP file which would cause an application to enter an infinite loop and not respond to user input when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0753 to this issue. During a security audit Chris Evans discovered a stack and a heap overflow in the XPM image decoder. An attacker could create a carefully crafted XPM file which could cause an application linked with gtk2 to crash or possibly execute arbitrary code when the file was opened by a victim. (CAN-2004-0782, CAN-2004-0783) Chris Evans also discovered an integer overflow in the ICO image decoder. An attacker could create a carefully crafted ICO file which could cause an application linked with gtk2 to crash when the file was opened by a victim. (CAN-2004-0788) --------------------------------------------------------------------- * Tue Sep 07 2004 Matthias Clasen - 2.4.7-2.4 - Fix issues in the xpm and ico loaders found by Chris Evans (#130711) * Fri Aug 20 2004 Owen Taylor - 2.4.7-2.2 - Fix problem with infinite loop on bad BMP data (#130450, test BMP from Chris Evans, fixfrom Manish Singh) * Sat Aug 14 2004 Matthias Clasen 2.4.7-1 - update to 2.4.7 * Fri Aug 13 2004 Matthias Clasen 2.4.6-1 - update to 2.4.6 - call libtoolize --force to win .so's back... * Fri Jul 30 2004 Jonathan Blandford 2.4.4-4 - add typeahead patch to GtkTreeView - automake-1.9 * Tue Jul 27 2004 Matthias Clasen - 2.4.4-3 - Use -64 suffix on powerpc64. (#128605) * Fri Jul 16 2004 Matthias Clasen - 2.4.4-2 - Fix permissions of gdk-pixbuf-csource script. - Escape macros in %changelog * Fri Jul 09 2004 Matthias Clasen - 2.4.4-1 - Update to 2.4.4 * Thu Jul 08 2004 Matthias Clasen - 2.4.1-5 - Look for the gtk.immodules file in the right location. (#127073) * Thu Jul 08 2004 Matthias Clasen - 2.4.1-4 - Add a wrapper for gdk-pixbuf-csource. * Wed Jun 23 2004 Matthias Clasen - 2.4.1-3 - Don't install testgtk and testtext - Rename binaries to -32/-64 (#124478) - Move arch-dependent config files to /etc/gtk-2.0/$host (#124482) - Add wrappers for updating the arch-dependent config files * Tue Jun 15 2004 Elliot Lee - rebuilt * Thu May 20 2004 Matthias Clasen - 2.4.1-1 - Upgrade to 2.4.1 --------------------------------------------------------------------- This update can be downloaded from: 75a86a6d678f76a2f6238a992463005f SRPMS/gtk2-2.4.7-2.4.src.rpm f6923be90c1621e83a19df610213ff12 x86_64/gtk2-2.4.7-2.4.x86_64.rpm e46b3ea2a153749dcf6d5cdf38603ea6 x86_64/gtk2-devel-2.4.7-2.4.x86_64.rpm 81f2cf32b341d60fa766e638624a201c x86_64/debug/gtk2-debuginfo-2.4.7-2.4.x86_64.rpm b659bb38815921f415c45790d2c4b1c6 x86_64/gtk2-2.4.7-2.4.i386.rpm b659bb38815921f415c45790d2c4b1c6 i386/gtk2-2.4.7-2.4.i386.rpm 9d38f480c8ccb6857fc6cbdb322ac073 i386/gtk2-devel-2.4.7-2.4.i386.rpm 5099d6ef8357b99e90e9fa2fd9c28695 i386/debug/gtk2-debuginfo-2.4.7-2.4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . Critical patch released for gtk2on Fedora addressing multiple image parsing security flaws, emphasizing risks associated with both stack and heap overflows.. gtk2 Security,Fedora Update,Image Decoder Issue,Buffer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team
Updated qt packages that fix security issues in several of the imagedecoders are now available.. --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated qt packages fix security issues Advisory ID: RHSA-2004:414-01 Issue date: 2004-08-20 Updated on: 2004-08-20 Product: Red Hat Enterprise Linux CVE Names: CAN-2004-0691 CAN-2004-0692 CAN-2004-0693 --------------------------------------------------------------------- 1. Summary: Updated qt packages that fix security issues in several of the image decoders are now available. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: Qt is a software toolkit that simplifies the task of writing and maintaining GUI (Graphical User Interface) applications for the X Window System. During a security audit, Chris Evans discovered a heap overflow in the BMP image decoder in Qt versions prior to 3.3.3. An attacker could create a carefully crafted BMP file in such a way that it would cause an application linked with Qt to crash or possibly execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0691 to this issue. Additionally, various flaws were discovered in the GIF, XPM, and JPEG decoders in Qt versions prior to 3.3.3. An attacker could create carefully crafted image files in such a way that it could cause an application linked against Qt to crash when the file was opened by a victim. TheCommon Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0692 and CAN-2004-0693 to these issues. Users of Qt should update to these updated packages which contain backported patches and are not vulnerable to these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/ for more info): 128720 - CAN-2004-0691 BMP decoder heap overflow 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 3b684906082e180dddd38404dca633f4 qt-2.3.1-10.src.rpm i386: 4abae89892524349c1413e9edfe1c580 qt-2.3.1-10.i386.rpm f8a7bc552d89a93c8de95d31bbf3fb6c qt-Xt-2.3.1-10.i386.rpm ba3283b0ecab676ca709746c7b9aad17 qt-designer-2.3.1-10.i386.rpm f9542947d96f0a40694026bddc6088b3 qt-devel-2.3.1-10.i386.rpm 08a3108d33c0391926515c8831e80e32 qt-static-2.3.1-10.i386.rpm ia64: 7a5212ecdd3bdfd6e7c22430cab707ca qt-2.3.1-10.ia64.rpm 163badec57860c0751ee49a74a863197 qt-Xt-2.3.1-10.ia64.rpm 62890a5783dea02beb1bd19e2c2b9476 qt-designer-2.3.1-10.ia64.rpm 4dc9f6a9177f16561371b41701cc8ca3 qt-devel-2.3.1-10.ia64.rpm f5bb921423a761d4412a45d8407960e9 qt-static-2.3.1-10.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 3b684906082e180dddd38404dca633f4 qt-2.3.1-10.src.rpm ia64: 7a5212ecdd3bdfd6e7c22430cab707ca qt-2.3.1-10.ia64.rpm 163badec57860c0751ee49a74a863197 qt-Xt-2.3.1-10.ia64.rpm 62890a5783dea02beb1bd19e2c2b9476 qt-designer-2.3.1-10.ia64.rpm 4dc9f6a9177f16561371b41701cc8ca3 qt-devel-2.3.1-10.ia64.rpm f5bb921423a761d4412a45d8407960e9 qt-static-2.3.1-10.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 3b684906082e180dddd38404dca633f4 qt-2.3.1-10.src.rpm i386: 4abae89892524349c1413e9edfe1c580 qt-2.3.1-10.i386.rpm f8a7bc552d89a93c8de95d31bbf3fb6c qt-Xt-2.3.1-10.i386.rpm ba3283b0ecab676ca709746c7b9aad17 qt-designer-2.3.1-10.i386.rpm f9542947d96f0a40694026bddc6088b3 qt-devel-2.3.1-10.i386.rpm 08a3108d33c0391926515c8831e80e32 qt-static-2.3.1-10.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 3b684906082e180dddd38404dca633f4 qt-2.3.1-10.src.rpm i386: 4abae89892524349c1413e9edfe1c580 qt-2.3.1-10.i386.rpm f8a7bc552d89a93c8de95d31bbf3fb6c qt-Xt-2.3.1-10.i386.rpm ba3283b0ecab676ca709746c7b9aad17 qt-designer-2.3.1-10.i386.rpm f9542947d96f0a40694026bddc6088b3 qt-devel-2.3.1-10.i386.rpm 08a3108d33c0391926515c8831e80e32 qt-static-2.3.1-10.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: f798532e2259e3027eb64a86f471c989 qt-3.1.2-13.4.src.rpm i386: 171e31325a6974fe6b3161b0dd935e05 qt-3.1.2-13.4.i386.rpm 53450013bb108936c88d7a68797400b5 qt-MySQL-3.1.2-13.4.i386.rpm c5372ac10529b611504c48fd1876d32a qt-config-3.1.2-13.4.i386.rpm dde05008907a4402aeec64bd1fef25d8 qt-designer-3.1.2-13.4.i386.rpm 7e9621c8793aeece8c6697a301fdaf85 qt-devel-3.1.2-13.4.i386.rpm ia64: 0162f98d41303ed47435fd634a49aa16 qt-3.1.2-13.4.ia64.rpm 83f81146ad6ff84575f221104e109a10 qt-MySQL-3.1.2-13.4.ia64.rpm 0b81a3f2c8ab00775d533c30129fe314 qt-config-3.1.2-13.4.ia64.rpm d7ff6cb677ea02273909f44018a4de02 qt-designer-3.1.2-13.4.ia64.rpm c93acbc881f899cbd944f74c2710c1dd qt-devel-3.1.2-13.4.ia64.rpm ppc: 342ed7861c4723143f22841155837163 qt-3.1.2-13.4.ppc.rpm f95779e3c785a8ca620b795a50c3a2b7 qt-MySQL-3.1.2-13.4.ppc.rpm d89c0631d249d3596cb0b7f3715d8c71 qt-config-3.1.2-13.4.ppc.rpm b5c58797337ec1c953a127d145241d70 qt-designer-3.1.2-13.4.ppc.rpm 4138557b0f597ede980c64e4e74debd3 qt-devel-3.1.2-13.4.ppc.rpm s390: 57951d45d98f46fe6f2326b16f23ea1b qt-3.1.2-13.4.s390.rpm 98b7677e8b7fa4d84583cfe8e92a91f4 qt-MySQL-3.1.2-13.4.s390.rpm b9f50cd8f014e9e39249dbfbe17b1398 qt-config-3.1.2-13.4.s390.rpm 2c140a0776e2ce98c273b7e628d86d23 qt-designer-3.1.2-13.4.s390.rpm 5e23428d4621c10ca60bf29d7d2a6ed7 qt-devel-3.1.2-13.4.s390.rpm s390x: 8f95df939142d43f0078f5a770850bb2 qt-3.1.2-13.4.s390x.rpm 5cc08910b564eed93b3f78c05261a176 qt-MySQL-3.1.2-13.4.s390x.rpm 73c6e602b9a45864a82d16314deba9c0 qt-config-3.1.2-13.4.s390x.rpm eae10bfa4b34cfbfd29f09e4d7368728 qt-designer-3.1.2-13.4.s390x.rpm fff3b6f404743fa76b5ba21f3a18e20d qt-devel-3.1.2-13.4.s390x.rpm x86_64: 24fbbe3a8cc3a9636e64cbecb62c52c1 qt-3.1.2-13.4.x86_64.rpm b4ca1ae5a331c4d30d75d2dcd1e53280 qt-MySQL-3.1.2-13.4.x86_64.rpm a684d66936b37ed87281ce2f8a49448b qt-config-3.1.2-13.4.x86_64.rpm d945dc65e4120b87f0fa6c0a77c129ee qt-designer-3.1.2-13.4.x86_64.rpm 814f662f0561c1dc07cb60a287487494 qt-devel-3.1.2-13.4.x86_64.rpm Red Hat Desktop version 3: SRPMS: f798532e2259e3027eb64a86f471c989 qt-3.1.2-13.4.src.rpm i386: 171e31325a6974fe6b3161b0dd935e05 qt-3.1.2-13.4.i386.rpm 53450013bb108936c88d7a68797400b5 qt-MySQL-3.1.2-13.4.i386.rpm c5372ac10529b611504c48fd1876d32a qt-config-3.1.2-13.4.i386.rpm dde05008907a4402aeec64bd1fef25d8 qt-designer-3.1.2-13.4.i386.rpm 7e9621c8793aeece8c6697a301fdaf85 qt-devel-3.1.2-13.4.i386.rpm x86_64: 24fbbe3a8cc3a9636e64cbecb62c52c1 qt-3.1.2-13.4.x86_64.rpm b4ca1ae5a331c4d30d75d2dcd1e53280 qt-MySQL-3.1.2-13.4.x86_64.rpm a684d66936b37ed87281ce2f8a49448b qt-config-3.1.2-13.4.x86_64.rpm d945dc65e4120b87f0fa6c0a77c129ee qt-designer-3.1.2-13.4.x86_64.rpm 814f662f0561c1dc07cb60a287487494 qt-devel-3.1.2-13.4.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: f798532e2259e3027eb64a86f471c989 qt-3.1.2-13.4.src.rpm i386: 171e31325a6974fe6b3161b0dd935e05 qt-3.1.2-13.4.i386.rpm 53450013bb108936c88d7a68797400b5 qt-MySQL-3.1.2-13.4.i386.rpm c5372ac10529b611504c48fd1876d32a qt-config-3.1.2-13.4.i386.rpm dde05008907a4402aeec64bd1fef25d8 qt-designer-3.1.2-13.4.i386.rpm 7e9621c8793aeece8c6697a301fdaf85 qt-devel-3.1.2-13.4.i386.rpm ia64: 0162f98d41303ed47435fd634a49aa16 qt-3.1.2-13.4.ia64.rpm 83f81146ad6ff84575f221104e109a10 qt-MySQL-3.1.2-13.4.ia64.rpm 0b81a3f2c8ab00775d533c30129fe314 qt-config-3.1.2-13.4.ia64.rpm d7ff6cb677ea02273909f44018a4de02 qt-designer-3.1.2-13.4.ia64.rpm c93acbc881f899cbd944f74c2710c1dd qt-devel-3.1.2-13.4.ia64.rpm x86_64: 24fbbe3a8cc3a9636e64cbecb62c52c1 qt-3.1.2-13.4.x86_64.rpm b4ca1ae5a331c4d30d75d2dcd1e53280 qt-MySQL-3.1.2-13.4.x86_64.rpm a684d66936b37ed87281ce2f8a49448b qt-config-3.1.2-13.4.x86_64.rpm d945dc65e4120b87f0fa6c0a77c129ee qt-designer-3.1.2-13.4.x86_64.rpm 814f662f0561c1dc07cb60a287487494 qt-devel-3.1.2-13.4.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: f798532e2259e3027eb64a86f471c989 qt-3.1.2-13.4.src.rpm i386: 171e31325a6974fe6b3161b0dd935e05 qt-3.1.2-13.4.i386.rpm 53450013bb108936c88d7a68797400b5 qt-MySQL-3.1.2-13.4.i386.rpm c5372ac10529b611504c48fd1876d32a qt-config-3.1.2-13.4.i386.rpm dde05008907a4402aeec64bd1fef25d8 qt-designer-3.1.2-13.4.i386.rpm 7e9621c8793aeece8c6697a301fdaf85 qt-devel-3.1.2-13.4.i386.rpm ia64: 0162f98d41303ed47435fd634a49aa16 qt-3.1.2-13.4.ia64.rpm 83f81146ad6ff84575f221104e109a10 qt-MySQL-3.1.2-13.4.ia64.rpm 0b81a3f2c8ab00775d533c30129fe314 qt-config-3.1.2-13.4.ia64.rpm d7ff6cb677ea02273909f44018a4de02 qt-designer-3.1.2-13.4.ia64.rpm c93acbc881f899cbd944f74c2710c1dd qt-devel-3.1.2-13.4.ia64.rpm x86_64: 24fbbe3a8cc3a9636e64cbecb62c52c1 qt-3.1.2-13.4.x86_64.rpm b4ca1ae5a331c4d30d75d2dcd1e53280 qt-MySQL-3.1.2-13.4.x86_64.rpm a684d66936b37ed87281ce2f8a49448b qt-config-3.1.2-13.4.x86_64.rpm d945dc65e4120b87f0fa6c0a77c129ee qt-designer-3.1.2-13.4.x86_64.rpm 814f662f0561c1dc07cb60a287487494 qt-devel-3.1.2-13.4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from 7. References: https://store.yourbrand.ca/domain/trolltech.com/developer/changes/changes-3.3.3.html CVE -CVE-2004-0691 CVE -CVE-2004-0692 CVE-CVE-2004-0693 8. Contact: The Red Hat security contact is . More contact details at Copyright 2004 Red Hat, Inc. . Updated Qt packages resolve critical heap overflow issues in image decoders across Red Hat Enterprise Linux.. Red Hat, Qt, security patches, image decoder issues, heap overflow. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.