Backport upstream exif fixes. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-685f0029c7 2021-11-17 01:12:41.170075 --------------------------------------------------------------------------------Name : digikam Product : Fedora 35 Version : 7.3.0 Release : 4.fc35 URL : https://www.digikam.org/ Summary : A digital camera accessing & photo management application Description : digiKam is an easy to use and powerful digital photo management application, which makes importing, organizing and manipulating digital photos a "snap". An easy to use interface is provided to connect to your digital camera, preview the images and download and/or delete them. digiKam built-in image editor makes the common photo correction a simple task. --------------------------------------------------------------------------------Update Information: Backport upstream exif fixes --------------------------------------------------------------------------------ChangeLog: * Fri Nov 5 2021 Rex Dieter - 7.3.0-4 - rebuild (ImageMagick) * Thu Nov 4 2021 Rex Dieter - 7.3.0-3 - backport exiv2-related upstream fixes (kde#439785, rh#2019835) --------------------------------------------------------------------------------References: [ 1 ] Bug #2019835 - Digikam can no longer update image metadata https://bugzilla.redhat.com/show_bug.cgi?id=2019835 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-685f0029c7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update for podman is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: podman security update Advisory ID: RHSA-2020:2117-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://access.redhat.com/errata/RHSA-2020:2117 Issue date: 2020-05-12 CVE Names: CVE-2020-8945 CVE-2020-10696 ==================================================================== 1. Summary: An update for podman is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux 7 Extras - noarch, ppc64le, s390x, x86_64 3. Description: The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. Security Fix(es): * buildah: Crafted input tar file may lead to local file overwrite during image build process (CVE-2020-10696) * proglottis/gpgme: Use-after-free in GPGME bindings during container image pull (CVE-2020-8945) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 1795838 - CVE-2020-8945 proglottis/gpgme: Use-after-free in GPGME bindings during container image pull 1817651 - CVE-2020-10696 buildah: Crafted input tar file may lead to local file overwrite during image build process 6. Package List: Red Hat Enterprise Linux 7 Extras: Source: podman-1.6.4-18.el7_8.src.rpm noarch: podman-docker-1.6.4-18.el7_8.noarch.rpm ppc64le: podman-1.6.4-18.el7_8.ppc64le.rpm podman-debuginfo-1.6.4-18.el7_8.ppc64le.rpm s390x: podman-1.6.4-18.el7_8.s390x.rpm podman-debuginfo-1.6.4-18.el7_8.s390x.rpm x86_64: podman-1.6.4-18.el7_8.x86_64.rpm podman-debuginfo-1.6.4-18.el7_8.x86_64.rpm Red Hat Enterprise Linux 7 Extras: Source: podman-1.6.4-18.el7_8.src.rpm noarch: podman-docker-1.6.4-18.el7_8.noarch.rpm x86_64: podman-1.6.4-18.el7_8.x86_64.rpm podman-debuginfo-1.6.4-18.el7_8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-8945 https://access.redhat.com/security/cve/CVE-2020-10696 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXrr+ZNzjgjWX9erEAQiSqhAAlYqZcvuO01y9wZxbsnZBwZYOurO01tOZ vz2T/5C5qilCkwamf6+Rn5MOKlhRlMhE2BiASs9OMvbsGzD86nOVI1/uBZ9LcIaQ flnSQ/p2RT6C67YL97Ne1hucXDJBue6pHBgtcUt8vRB1flVRUI1DU1dK2CnuTs9Z Mp14DJSY2HNIKYWyDJ6FovSozPTc2z3BtZQM5wa/suSdRKmrpJzC0Xky1u7tfk6W l9HhDypUqS7h901xtE91aom/KxXnVoG3B2Notc0II3aq97kShakrICFK0CK80cNV vMCMbXsItEekNyP+wXlfyOY1ef8XV45Tjpm6Nmx8o/oCLcjF/56FslykbZKCDOUA Qch+FMVRJV0vFcv9cIXNNmkCFxF+s3RY7VmgBTbNJE8rmMJb5KAtJ/DJZf4li8XC WytedOlgZrpPiHWl4Zy8AhasleXGVJP9oxfdBu7uBFclF2lQIWgjBQaQwuRU2NO2 IQ7fETbdVEkFnLVGn7F0vxtlp1F7va0NxXwHQAIMQknyfxmuhNX+rPI6Cl2id5Yb Rs/GEFTI+qbtfWJSGKAEPFvPvfiucRCRpSG8S6aKKNYvRhLxmVFkWp6n8iMSpJrr qjnxko7/hoR+azWLB/1uKlrcav7/Lew72iKQXOf7GelLmM2DA1ixdMpVn+ck1N13 1mdoJoJHKyk=43Fw -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Updated openstack-glance packages that fix two security issues are now available for Red Hat Enterprise Linux OpenStack Platform 5.0, 6.0, and 7.0. [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-glance security update Advisory ID: RHSA-2015:1897-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2015:1897.html Issue date: 2015-10-15 CVE Names: CVE-2015-5251 CVE-2015-5286 ==================================================================== 1. Summary: Updated openstack-glance packages that fix two security issues are now available for Red Hat Enterprise Linux OpenStack Platform 5.0, 6.0, and 7.0. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6 - noarch Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7 - noarch Red Hat Enterprise Linux OpenStack Platform 6.0 for RHEL 7 - noarch Red Hat Enterprise Linux OpenStack Platform 7.0 for RHEL 7 - noarch 3. Description: OpenStack Image service (glance) provides discovery, registration, and delivery services for disk and server images. It provides the ability to copy or snapshot a server image, and immediately store it away. Stored images can be used as a template to get new servers up and running quickly and more consistently than installing a server operating system and individually configuring additional services. A flaw was discovered in the OpenStack Image service where a tenant could manipulate the status of their images by submitting an HTTP PUT request together with an 'x-image-meta-status' header. A malicious tenant could exploit this flawto reactivate disabled images, bypass storage quotas, and in some cases replace image contents (where they have owner access). Setups using the Image service's v1 API could allow the illegal modification of image status. Additionally, setups which also use the v2 API could allow a subsequent re-upload of image contents. (CVE-2015-5251) A race-condition flaw was discovered in the OpenStack Image service. When images in the upload state were deleted using a token close to expiration, untracked image data could accumulate in the back end. Because untracked data does not count towards the storage quota, an attacker could use this flaw to cause a denial of service through resource exhaustion. (CVE-2015-5286) Red Hat would like to thank the OpenStack project for reporting these issues. Upstream acknowledges Hemanth Makkapati of Rackspace as the original reporter of CVE-2015-5251, and Mike Fedosin and Alexei Galkin of Mirantis as the original reporters of CVE-2015-5286. All openstack-glance users are advised to upgrade to these updated packages, which correct these issues. After installing the updated packages, running Image service services will be restarted automatically. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1263511 - CVE-2015-5251 openstack-glance allows illegal modification of image status 1267516 - CVE-2015-5286 openstack-glance: Storage overrun by deleting images 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6: Source: openstack-glance-2014.1.5-3.el6ost.src.rpm noarch: openstack-glance-2014.1.5-3.el6ost.noarch.rpm openstack-glance-doc-2014.1.5-3.el6ost.noarch.rpm python-glance-2014.1.5-3.el6ost.noarch.rpm Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL7: Source: openstack-glance-2014.1.5-3.el7ost.src.rpm noarch: openstack-glance-2014.1.5-3.el7ost.noarch.rpm openstack-glance-doc-2014.1.5-3.el7ost.noarch.rpm python-glance-2014.1.5-3.el7ost.noarch.rpm Red Hat Enterprise Linux OpenStack Platform 6.0 for RHEL 7: Source: openstack-glance-2014.2.3-3.el7ost.src.rpm noarch: openstack-glance-2014.2.3-3.el7ost.noarch.rpm openstack-glance-doc-2014.2.3-3.el7ost.noarch.rpm python-glance-2014.2.3-3.el7ost.noarch.rpm Red Hat Enterprise Linux OpenStack Platform 7.0 for RHEL 7: Source: openstack-glance-2015.1.1-3.el7ost.src.rpm noarch: openstack-glance-2015.1.1-3.el7ost.noarch.rpm openstack-glance-doc-2015.1.1-3.el7ost.noarch.rpm python-glance-2015.1.1-3.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2015-5251 https://access.redhat.com/security/cve/CVE-2015-5286 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2015 Red Hat, Inc. . The latest openstack-glance updates fix security vulnerabilities in Red Hat Enterprise Linux OpenStack Platform. Discover further details!. OpenStack Image Services, Red Hat Enterprise Linux, OpenStack Security Advisory. . LinuxSecurity.com Team
Updated openstack-glance packages that fix multiple bugs and add various enhancements are now available for Red Hat OpenStack Essex. 2. Relevant releases/architectures: [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Low: openstack-glance security update Advisory ID: RHSA-2012:1558-01 Product: Red Hat OpenStack Advisory URL: https://access.redhat.com/errata/RHSA-2012:1558.html Issue date: 2012-12-10 CVE Names: CVE-2012-4573 ==================================================================== 1. Summary: Updated openstack-glance packages that fix multiple bugs and add various enhancements are now available for Red Hat OpenStack Essex. 2. Relevant releases/architectures: RHOS Essex Release - noarch 3. Description: The openstack-glance packages allows virtual machine images to be discovered, registered and retrieved. It also includes a RESTful API to provide these services to other applications. The openstack-glance packages have been upgraded to upstream version 2012.1.2, which provide a number of bug fixes and enhancements over the previous version. A flaw in Keystone allowed an attacker with access to the web and network interfaces to delete arbitrary, non-protected images from Glance servers. (CVE-2012-4573) Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Gabe Westmaas as the original reporter of CVE-2012-4573. All users of openstack-glance are advised to upgrade to these updated packages, which fix these bugs and add these enhancements. After installing the updated packages, the Glance services (openstack-glance-api and openstack-glance-registry) will be restarted automatically. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this updateare available at https://access.redhat.com/knowledge/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 872302 - CVE-2012-4573 OpenStack: Glance Authentication bypass for image deletion 6. Package List: RHOS Essex Release: Source: noarch: openstack-glance-2012.1.2-2.el6.noarch.rpm openstack-glance-doc-2012.1.2-2.el6.noarch.rpm python-glance-2012.1.2-2.el6.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2012-4573 https://access.redhat.com/security/updates/classification/#low 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2012 Red Hat, Inc. . Canonical advises OpenStack-glance users to upgrade for improved security features, primarily enhanced safeguards against unauthorized image removals. OpenStack Security, Red Hat Update, Image Management, Low Severity Alert. . Severity: Low. LinuxSecurity.com Team
Updated ImageMagick packages that fix one security issue and one bug are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: ImageMagick security and bug fix update Advisory ID: RHSA-2010:0652-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2010:0652.html Issue date: 2010-08-25 CVE Names: CVE-2009-1882 ==================================================================== 1. Summary: Updated ImageMagick packages that fix one security issue and one bug are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Description: ImageMagick is an image display and manipulation tool for the X Window System that can read and write multiple image formats. An integer overflow flaw, leading to a heap-based buffer overflow, was found in the ImageMagick routine responsible for creating X11 images. An attacker could create a specially-crafted image file that, when opened by a victim, would cause ImageMagick to crash or, potentially, execute arbitrary code. (CVE-2009-1882) This update also fixes the following bug: * previously, portions of certain RGB images on the right side were not rendered and left black when converting or displaying them. Withthis update, RGB images display correctly. (BZ#625058) Users of ImageMagick are advised to upgrade to these updated packages, which contain backported patches to correct these issues. All running instances of ImageMagick must be restarted for this update to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 503017 - CVE-2009-1882 ImageMagick, GraphicsMagick: Integer overflow in the routine creating X11 images 625058 - CRM.1902920 - Issue displaying SGI image with ImageMagick 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: ImageMagick-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-perl-6.2.8.0-4.el5_5.2.i386.rpm x86_64: ImageMagick-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-perl-6.2.8.0-4.el5_5.2.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.i386.rpm x86_64: ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: ImageMagick-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-perl-6.2.8.0-4.el5_5.2.i386.rpm ia64: ImageMagick-6.2.8.0-4.el5_5.2.ia64.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.ia64.rpm ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.ia64.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.ia64.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.ia64.rpm ImageMagick-perl-6.2.8.0-4.el5_5.2.ia64.rpm ppc: ImageMagick-6.2.8.0-4.el5_5.2.ppc.rpm ImageMagick-6.2.8.0-4.el5_5.2.ppc64.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.ppc.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.ppc64.rpm ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.ppc.rpm ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.ppc64.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.ppc.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.ppc64.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.ppc.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.ppc64.rpm ImageMagick-perl-6.2.8.0-4.el5_5.2.ppc.rpm s390x: ImageMagick-6.2.8.0-4.el5_5.2.s390.rpm ImageMagick-6.2.8.0-4.el5_5.2.s390x.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.s390.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.s390x.rpm ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.s390.rpm ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.s390x.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.s390.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.s390x.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.s390.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.s390x.rpm ImageMagick-perl-6.2.8.0-4.el5_5.2.s390x.rpm x86_64: ImageMagick-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-debuginfo-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-perl-6.2.8.0-4.el5_5.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2009-1882 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2010 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFMdRWcXlSAg2UNWIIRAu6pAKCeBhHxBOdZqQQMrjdvEKSu+1e2HwCeMbHr Suvtw2PQaTymC4bGniy2Ibg=2E2F -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
The Gallery developers have discovered a potentially serious security flaw in Gallery 1.3.1, 1.3.2, 1.3.3, 1.4 and 1.4.1 which can a remote exploit of your webserver. [More...] . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200402-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ~ https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ~ Severity: Normal ~ Title: Gallery
Get the latest Linux and open source security news straight to your inbox.