Apply upstream libtiff fix for CVE-2022-4645. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-40b675d7ae 2023-03-16 18:18:56.871804 --------------------------------------------------------------------------------Name : tkimg Product : Fedora 36 Version : 1.4.14 Release : 3.fc36 URL : https://sourceforge.net/projects/tkimg/ Summary : Image support library for Tk Description : This package contains a collection of image format handlers for the Tk photo image type, and a new image type, pixmaps. --------------------------------------------------------------------------------Update Information: Apply upstream libtiff fix for CVE-2022-4645 --------------------------------------------------------------------------------ChangeLog: * Tue Mar 7 2023 Tom Callaway - 1.4.14-3 - apply upstream libtiff fix for CVE-2022-4645 * Sat Jan 21 2023 Fedora Release Engineering - 1.4.14-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2176220 - CVE-2022-4645 libtiff: out-of-bounds read in tiffcp in tools/tiffcp.c https://bugzilla.redhat.com/show_bug.cgi?id=2176220 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-40b675d7ae' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to latest upstream release. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-5312f6200c 2023-03-11 03:04:11.190128 --------------------------------------------------------------------------------Name : manifest-tool Product : Fedora 38 Version : 2.0.8 Release : 1.fc38 URL : https://github.com/estesp/manifest-tool Summary : A command line tool used for creating manifest list objects Description : This tool was mainly created for the purpose of viewing, creating, and pushing the new manifests list object type in the Docker registry. Manifest lists are defined in the v2.2 image specification and exist mainly for the purpose of supporting multi-architecture and/or multi-platform images within a Docker registry. --------------------------------------------------------------------------------Update Information: Update to latest upstream release --------------------------------------------------------------------------------ChangeLog: * Fri Mar 3 2023 Josh Boyer - 2.0.8-1 - Update to latest upstream release - Fixes RhBug 2174535 CVE-2023-25173 --------------------------------------------------------------------------------References: [ 1 ] Bug #2106664 - manifest-tool-2.0.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2106664 [ 2 ] Bug #2163549 - CVE-2022-3064 manifest-tool: go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2163549 [ 3 ] Bug #2174535 - manifest-tool: containerd: Supplementary groups are not set up properly [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2174535 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-5312f6200c' at the command line. For more information,refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.