libPGF could be made to crash if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4554-1 September 28, 2020 libpgf vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: libPGF could be made to crash if it opened a specially crafted file. Software Description: - libpgf: Progressive Graphics File (PGF) library Details: It was discovered that libPGF lacked proper validation when opening a specially crafted PGF file. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: libpgf6 6.14.12-3.1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4554-1 CVE-2015-6673 Package Information: https://launchpad.net/ubuntu/+source/libpgf/6.14.12-3.1ubuntu0.1 . Ubuntu Security Announcement USN-4554-1 pertains to a security flaw in libpgf that could lead to denial of service. It outlines remedial measures to mitigate the risk.. libpgf vulnerability, Ubuntu update, denial of service, security issues, crash exploit. . Severity: Critical. LinuxSecurity.com Team
An issue has been found in libpgf, a library to handle Progressive Graphics File (PGF). . Package : libpgf Version : 6.14.12-3+deb8u1 CVE ID : CVE-2015-6673 An issue has been found in libpgf, a library to handle Progressive Graphics File (PGF). Due to lack of validation of ColorTableSize, a use-after-free issue might appear in Decoder.cpp For Debian 8 "Jessie", this problem has been fixed in version 6.14.12-3+deb8u1. We recommend that you upgrade your libpgf packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade libpgf to address security risks concerning flaws in color table validation mechanisms.. libpgf Security Update, Debian 8, Use-After-Free Issue. . LinuxSecurity.com Team
Use-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32 (CVE-2015-6673). References: - https://bugs.mageia.org/show_bug.cgi?id=24101 . MGASA-2019-0014 - Updated libpgf packages fix security vulnerability Publication date: 05 Jan 2019 URL: https://advisories.mageia.org/MGASA-2019-0014.html Type: security Affected Mageia releases: 6 CVE: CVE-2015-6673 Use-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32 (CVE-2015-6673). References: - https://bugs.mageia.org/show_bug.cgi?id=24101 - https://www.openwall.com/lists/oss-security/2015/08/25/9 - https://www.cve.org/CVERecord?id=CVE-2015-6673 SRPMS: - 6/core/libpgf-6.12.24-7.1.mga6 . Recent updates to libpgf packages resolve a critical use-after-free vulnerability affecting Mageia systems. Find out more regarding the dissemination of the security advisory.. use-after-free, libpgf, security update, Mageia advisory, software patch. . Severity: Critical. LinuxSecurity.com Team
Backport upstream fixes: Use-after-free bug in Decoder.cpp. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-13336 2015-08-12 19:48:33 -------------------------------------------------------------------------------- Name : libpgf Product : Fedora 23 Version : 6.14.12 Release : 4.fc23 URL : https://libpgf.org/ Summary : PGF (Progressive Graphics File) library Description : libPGF contains an implementation of the Progressive Graphics File (PGF) which is a new image file format, that is based on a discrete, fast wavelet transform with progressive coding features. PGF can be used for lossless and lossy compression. -------------------------------------------------------------------------------- Update Information: Backport upstream fixes: Use-after-free bug in Decoder.cpp -------------------------------------------------------------------------------- References: [ 1 ] Bug #1251749 - Use-after-free bug in Decoder.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1251749 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libpgf' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.