Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security fix for CVE-2017-2586, CVE-2017-2587 and CVE-2017-5849, ---- Add license information file copyright_summary ---- New version of netpbm is available (10.77.00) ---- add missing directives about bundled libraries jasper and jbigkit ---- New version of netpbm is available (10.76.00). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-fa4e441e03 2017-03-01 20:09:34.153395 -------------------------------------------------------------------------------- Name : netpbm Product : Fedora 24 Version : 10.77.00 Release : 3.fc24 URL : https://netpbm.sourceforge.net/ Summary : A library for handling different graphics file formats Description : The netpbm package contains a library of functions which support programs for handling various graphics file formats, including .pbm (portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps), .ppm (portable pixmaps) and others. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2017-2586, CVE-2017-2587 and CVE-2017-5849, ---- Add license information file copyright_summary ---- New version of netpbm is available (10.77.00) ---- add missing directives about bundled libraries jasper and jbigkit ---- New version of netpbm is available (10.76.00) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1419650 - CVE-2017-5849 netpbm: Calls TIFFRGBA with width and height parameters switched https://bugzilla.redhat.com/show_bug.cgi?id=1419650 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade netpbm' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPGkeys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
FFmpeg could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-1706-1 January 28, 2013 ffmpeg vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.04 LTS Summary: FFmpeg could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - ffmpeg: multimedia player, server and encoder Details: It was discovered that FFmpeg incorrectly handled certain malformed media files. If a user were tricked into opening a crafted media file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.04 LTS: libavcodec52 4:0.5.9-0ubuntu0.10.04.3 libavformat52 4:0.5.9-0ubuntu0.10.04.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1706-1 CVE-2012-2783, CVE-2012-2803 Package Information: https://launchpad.net/ubuntu/+source/ffmpeg/4:0.5.9-0ubuntu0.10.04.3 . Flaws in FFmpeg may cause application crashes or enable code execution through specially designed media files on Ubuntu systems.. FFmpeg Security, Ubuntu Vulnerabilities, Application Crash, Code Execution, Media Files. . Severity: Critical. LinuxSecurity.com Team
Updated gstreamer-plugins packages that fix one security issue are now available for Red Hat Enterprise Linux 4. This update has been rated as having important security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: gstreamer-plugins security update Advisory ID: RHSA-2009:0270-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:0270.html Issue date: 2009-02-06 CVE Names: CVE-2009-0397 ==================================================================== 1. Summary: Updated gstreamer-plugins packages that fix one security issue are now available for Red Hat Enterprise Linux 4. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Description: The gstreamer-plugins package contains plugins used by the GStreamer streaming-media framework to support a wide variety of media types. A heap buffer overflow was found in the GStreamer's QuickTime media file format decoding plug-in. An attacker could create a carefully-crafted QuickTime media .mov file that would cause an application using GStreamer to crash or, potentially, execute arbitrary code if played by a victim. (CVE-2009-0397) All users of gstreamer-plugins are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. After installing the update, all applications using GStreamer (such as rhythmbox) must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure that allpreviously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 481267 - CVE-2009-0397 gstreamer-plugins, gstreamer-plugins-good: heap-based buffer overflow while parsing malformed QuickTime media files via crafted Time-to-sample (stss) atom data 6. Package List: Red Hat Enterprise Linux AS version 4: Source: i386: gstreamer-plugins-0.8.5-1.EL.2.i386.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.i386.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.i386.rpm ia64: gstreamer-plugins-0.8.5-1.EL.2.ia64.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.ia64.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.ia64.rpm ppc: gstreamer-plugins-0.8.5-1.EL.2.ppc.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.ppc.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.ppc.rpm s390: gstreamer-plugins-0.8.5-1.EL.2.s390.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.s390.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.s390.rpm s390x: gstreamer-plugins-0.8.5-1.EL.2.s390x.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.s390x.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.s390x.rpm x86_64: gstreamer-plugins-0.8.5-1.EL.2.x86_64.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.x86_64.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: gstreamer-plugins-0.8.5-1.EL.2.i386.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.i386.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.i386.rpm x86_64: gstreamer-plugins-0.8.5-1.EL.2.x86_64.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.x86_64.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.x86_64.rpm Red Hat Enterprise Linux ES version4: Source: i386: gstreamer-plugins-0.8.5-1.EL.2.i386.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.i386.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.i386.rpm ia64: gstreamer-plugins-0.8.5-1.EL.2.ia64.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.ia64.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.ia64.rpm x86_64: gstreamer-plugins-0.8.5-1.EL.2.x86_64.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.x86_64.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: gstreamer-plugins-0.8.5-1.EL.2.i386.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.i386.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.i386.rpm ia64: gstreamer-plugins-0.8.5-1.EL.2.ia64.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.ia64.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.ia64.rpm x86_64: gstreamer-plugins-0.8.5-1.EL.2.x86_64.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.2.x86_64.rpm gstreamer-plugins-devel-0.8.5-1.EL.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2009-0397 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2009 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFJjDRVXlSAg2UNWIIRAtk5AJwND0VW4IIW9HBgtXj0GM05HEVswACfddPE D8x4fXoCXrjSA54UVzBd1KI=YloF -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Get the latest Linux and open source security news straight to your inbox.