imageio can attempt to download shared freeimage libraries from https://github.com/imageio/imageio-binaries/tree/master/freeimage. The code fetches straight from master and provides no way of verifying whether the correct file was fetched. As a result, if the repository is attacked in the future, all prior versions of imageio would be silently . MGASA-2024-0244 - Updated python-imageio packages fix security vulnerability Publication date: 01 Jul 2024 URL: https://advisories.mageia.org/MGASA-2024-0244.html Type: security Affected Mageia releases: 9 imageio can attempt to download shared freeimage libraries from https://github.com/imageio/imageio-binaries/tree/master/freeimage. The code fetches straight from master and provides no way of verifying whether the correct file was fetched. As a result, if the repository is attacked in the future, all prior versions of imageio would be silently downloading arbitrary shared libraries and running them on user systems. This is a serious problem. References: - https://bugs.mageia.org/show_bug.cgi?id=31016 SRPMS: - 9/core/python-imageio-2.22.4-1.1.mga9 . The latest python-imageio updates resolve a major security vulnerability in Mageia. Enhancements included thwart possible library exploitation.. mageia security, python imageio, software update, library risk. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.