Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2427-1
KAuth allows to pass parameters with arbitrary types to helpers running as root over DBus. Certain types can cause crashes and trigger decoding arbitrary images with dynamically loaded plugins. References: . MGASA-2019-0083 - Updated kauth packages fix security vulnerability Publication date: 14 Feb 2019 URL: https://advisories.mageia.org/MGASA-2019-0083.html Type: security Affected Mageia releases: 6 KAuth allows to pass parameters with arbitrary types to helpers running as root over DBus. Certain types can cause crashes and trigger decoding arbitrary images with dynamically loaded plugins. References: - https://bugs.mageia.org/show_bug.cgi?id=24334 - https://kde.org/info/security/advisory-20190209-1.txt SRPMS: - 6/core/kauth-5.42.0-1.1.mga6 . MGASA-2019-0083 - Updated kauth packages fix security vulnerability Publication date: 14 Feb 2019 UR. kauth, allows, parameters, arbitrary, types, helpers, running, certain. . Severity: Critical. LinuxSecurity.com Team
New version of dcraw is available 9.28.0 Security fix for CVE-2018-5801. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-ae1ced8fb6 2018-07-25 18:44:08.975117 --------------------------------------------------------------------------------Name : dcraw Product : Fedora 27 Version : 9.28.0 Release : 1.fc27 URL : Summary : Tool for decoding raw image data from digital cameras Description : This package contains dcraw, a command line tool to decode raw image data downloaded from digital cameras. --------------------------------------------------------------------------------Update Information: New version of dcraw is available 9.28.0 Security fix for CVE-2018-5801 --------------------------------------------------------------------------------ChangeLog: * Thu Jun 14 2018 Josef Ridky - 9.28.0-1 - New upstream release 9.28.0 (#1585348) - Fix CVE-2018-5801 (#1557160) * Fri Feb 23 2018 Florian Weimer - 9.27.0-8 - Use LDFLAGS from redhat-rpm-config * Tue Feb 20 2018 Nils Philippsen - 9.27.0-7 - require gcc for building * Wed Feb 7 2018 Fedora Release Engineering - 9.27.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1553334 - CVE-2018-5801 LibRaw: NULL pointer dereference in LibRaw::unpack function src/libraw_cxx.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1553334 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-ae1ced8fb6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
libwmf-0.2.8.4-46.fc23 - Related: rhbz#1227244 CVE-2015-4696 fix patch context. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-14847 2015-09-04 19:45:14.259035 -------------------------------------------------------------------------------- Name : libwmf Product : Fedora 23 Version : 0.2.8.4 Release : 46.fc23 URL : https://wvware.sourceforge.net/libwmf.html Summary : Windows MetaFile Library Description : A library for reading and converting Windows MetaFile vector graphics (WMF). -------------------------------------------------------------------------------- Update Information: libwmf-0.2.8.4-46.fc23 - Related: rhbz#1227244 CVE-2015-4696 fix patch context -------------------------------------------------------------------------------- References: [ 1 ] Bug #1227244 - CVE-2015-0848 libwmf: heap overflow when decoding BMP images [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1227244 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libwmf' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
CVE-2015-0848 heap overflow when decoding BMP images CVE-2015-0848 heap overflow when decoding BMP images. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-9674 2015-06-09 09:02:57 -------------------------------------------------------------------------------- Name : libwmf Product : Fedora 21 Version : 0.2.8.4 Release : 43.fc21 URL : Summary : Windows MetaFile Library Description : A library for reading and converting Windows MetaFile vector graphics (WMF). -------------------------------------------------------------------------------- Update Information: CVE-2015-0848 heap overflow when decoding BMP images CVE-2015-0848 heap overflow when decoding BMP images -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 8 2015 Caolán McNamara - 0.2.8.4-43 - Resolves: rhbz#1227244 CVE-2015-0848 heap overflow when decoding BMP images * Tue Jun 2 2015 Caolán McNamara - 0.2.8.4-42 - Resolves: rhbz#1227244 CVE-2015-0848 heap overflow when decoding BMP images * Sat Feb 21 2015 Till Maas - 0.2.8.4-41 - Rebuilt for Fedora 23 Change https://fedoraproject.org/wiki/Changes/Harden_all_packages_with_position-independent_code -------------------------------------------------------------------------------- References: [ 1 ] Bug #1227243 - CVE-2015-0848, CVE-2015-4588 libwmf: heap overflow when decoding BMP images https://bugzilla.redhat.com/show_bug.cgi?id=1227243 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libwmf' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
The libtiff package contains a library of functions for manipulating TIFF (Tagged Image File Format) files. Tavis Ormandy of Google discovered a number of flaws in libtiff during a security audit. An attacker could create a carefully crafted TIFF file in such a way that it was possible to cause an application linked with libtiff to crash or possibly execute arbitrary code. (CVE-2006-3459, CVE-2006-3460, CVE-2006-3461, CVE-2006-3462, CVE-2006-3463, CVE-2006-3464, CVE-2006-3465) All users are advised to upgrade to these updated packages, which contain backported fixes for these issues.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-878 2006-08-02 ---------------------------------------------------------------------Product : Fedora Core 4 Name : libtiff Version : 3.7.1 Release : 6.fc4.3 Summary : A library of functions for manipulating TIFF format image files. Description : The libtiff package contains a library of functions for manipulating TIFF (Tagged Image File Format) image format files. TIFF is a widely used file format for bitmapped images. TIFF files usually end in the .tif extension and they are often quite large. The libtiff package should be installed if you need to manipulate TIFF format image files. ---------------------------------------------------------------------Update Information: The libtiff package contains a library of functions for manipulating TIFF (Tagged Image File Format) files. Tavis Ormandy of Google discovered a number of flaws in libtiff during a security audit. An attacker could create a carefully crafted TIFF file in such a way that it was possible to cause an application linked with libtiff to crash or possibly execute arbitrary code. (CVE-2006-3459, CVE-2006-3460, CVE-2006-3461, CVE-2006-3462, CVE-2006-3463, CVE-2006-3464, CVE-2006-3465) All users are advised to upgrade to these updated packages, which contain backported fixes for these issues. ---------------------------------------------------------------------* Tue Aug 1 2006 Matthias Clasen - Fix several vulnerabilities (CVE-2006-3460 CVE-2006-3461 CVE-2006-3462 CVE-2006-3463 CVE-2006-3464 CVE-2006-3465) ---------------------------------------------------------------------This update can be downloaded from: e25a0090188f4a25e04b23d9dabf8618dcd5560a SRPMS/libtiff-3.7.1-6.fc4.3.src.rpm e25a0090188f4a25e04b23d9dabf8618dcd5560a noarch/libtiff-3.7.1-6.fc4.3.src.rpm 0d920d3854947dd1b5ea6035f6462763e252d6c4 ppc/libtiff-3.7.1-6.fc4.3.ppc.rpm f39962656b7efcc8e657427ed2ef51df590aa216 ppc/libtiff-devel-3.7.1-6.fc4.3.ppc.rpm 5f7f56f8e3c0f504a2dc5960cb5d884e54f9c349 ppc/debug/libtiff-debuginfo-3.7.1-6.fc4.3.ppc.rpm 6e45b6be8f666e508e3de4b9c30aab09b57378a2 x86_64/libtiff-3.7.1-6.fc4.3.x86_64.rpm cee15750ace41bfa7e5a3b22d3883010a837febd x86_64/libtiff-devel-3.7.1-6.fc4.3.x86_64.rpm 9d9f9b1ceb5db2ac47667644eb5bd43944d69ea7 x86_64/debug/libtiff-debuginfo-3.7.1-6.fc4.3.x86_64.rpm 12dcfb0c2a959d9da7f581b4c1b93aca0861567d i386/libtiff-3.7.1-6.fc4.3.i386.rpm ad5847f0d6196a9782fc72e80a1b14fabfbffa93 i386/libtiff-devel-3.7.1-6.fc4.3.i386.rpm 6d158f79ae88e9e9fe44e776064bd108532b07f9 i386/debug/libtiff-debuginfo-3.7.1-6.fc4.3.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Multiple overflows have been found in the imlib2 library image decoding routines, potentially allowing the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200501-19 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: imlib2: Buffer overflows in image decoding Date: January 11, 2005 Bugs: #77002 ID: 200501-19 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple overflows have been found in the imlib2 library image decoding routines, potentially allowing the execution of arbitrary code. Background ========= imlib2 is an advanced replacement for image manipulation libraries such as libXpm. It is utilized by numerous programs, including gkrellm and several window managers, to display images. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/imlib2 < 1.2.0 > = 1.2.0 Description ========== Pavel Kankovsky discovered that several buffer overflows found in the libXpm library (see GLSA 200409-34) also apply to imlib (see GLSA 200412-03) and imlib2. He also fixed a number of other potential security vulnerabilities. Impact ===== A remote attacker could entice a user to view a carefully-crafted image file, which would potentially lead to the execution of arbitrary code with the rights of the user viewing the image. This affects any program that utilizes of the imlib2 library. Workaround ========= There is no known workaround at this time. Resolution ========= All imlib2 users should upgrade to thelatest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/imlib2-1.2.0" References ========= [ 1 ] CAN-2004-1026 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1026 [ 2 ] GLSA 200412-03 https://security.gentoo.org/glsa/200412-03 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200501-19 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
An integer overflow has been found in the TIFF library image decoding routines and the tiffdump utility, potentially allowing arbitrary code execution. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200501-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: tiff: New overflows in image decoding Date: January 05, 2005 Bugs: #75213 ID: 200501-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An integer overflow has been found in the TIFF library image decoding routines and the tiffdump utility, potentially allowing arbitrary code execution. Background ========= The TIFF library contains encoding and decoding routines for the Tag Image File Format. It is called by numerous programs, including GNOME and KDE applications, to interpret TIFF images. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/tiff < 3.7.1-r1 > = 3.7.1-r1 Description ========== infamous41md found a potential integer overflow in the directory entry count routines of the TIFF library (CAN-2004-1308). Dmitry V. Levin found another similar issue in the tiffdump utility (CAN-2004-1183). Impact ===== A remote attacker could entice a user to view a carefully crafted TIFF image file, which would potentially lead to execution of arbitrary code with the rights of the user viewing the image. This affects any program that makes use of the TIFF library, including many web browsers or mail readers. Workaround ========= There is no known workaround at thistime. Resolution ========= All TIFF library users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/tiff-3.7.1-r1" References ========= [ 1 ] CAN-2004-1183 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1183 [ 2 ] CAN-2004-1308 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1308 [ 3 ] iDEFENSE Advisory ;type=vulnerabilities Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200501-06 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.