MinGW cross compiled gdk-pixbuf 2.36.12 release, fixing various CVE's.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-a718b79006 2020-02-08 01:36:33.446568 --------------------------------------------------------------------------------Name : mingw-gdk-pixbuf Product : Fedora 30 Version : 2.36.12 Release : 1.fc30 URL : Summary : MinGW Windows GDK Pixbuf library Description : MinGW Windows GDK Pixbuf library. --------------------------------------------------------------------------------Update Information: MinGW cross compiled gdk-pixbuf 2.36.12 release, fixing various CVE's. --------------------------------------------------------------------------------ChangeLog: * Tue Jan 28 2020 Kalev Lember - 2.36.12-1 - Update to 2.36.12 * Tue Oct 8 2019 Sandro Mani - 2.36.11-6 - Rebuild (Changes/Mingw32GccDwarf2) * Thu Jul 25 2019 Fedora Release Engineering - 2.36.11-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1378897 - CVE-2015-7552 mingw-gdk-pixbuf: gdk-pixbuf: Heap-based buffer overflow in the gdk_pixbuf_flip function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1378897 [ 2 ] Bug #1427226 - CVE-2017-6313 CVE-2017-6314 CVE-2017-6312 CVE-2017-6311 mingw-gdk-pixbuf: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1427226 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-a718b79006' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.