Dan Smith discovered that nova, a cloud computing fabric controller, calls qemu-img without format restrictions for resize, which may result in unsafe image resize operations that could destroy data on the host system. Only compute nodes using the Flat image backend are affected. For Debian 11 bullseye, this problem has been fixed in version. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4486-1
Fixes a security vulnerability on certain resize operations with '--resize-method=box'. References: - https://bugs.mageia.org/show_bug.cgi?id=29458 . MGASA-2021-0437 - Updated gifsicle packages fix security vulnerability Publication date: 23 Sep 2021 URL: https://advisories.mageia.org/MGASA-2021-0437.html Type: security Affected Mageia releases: 8 Fixes a security vulnerability on certain resize operations with '--resize-method=box'. References: - https://bugs.mageia.org/show_bug.cgi?id=29458 - - http://www.lcdf.org/gifsicle/changes.html SRPMS: - 8/core/gifsicle-1.93-1.mga8 . Mageia 2021-0452 addresses a moderate severity vulnerability within pngcrush image transformation functions. For further information, continue reading.. Mageia Gifsicle Update, Security Fix, Resize Issue. . Severity: Medium. LinuxSecurity.com Team
An update that contains security fixes can now be installed. . openSUSE Security Update: Security update for gifsicle ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1249-1 Rating: moderate References: Affected Products: openSUSE Leap 15.2 openSUSE Backports SLE-15-SP3 openSUSE Backports SLE-15-SP2 openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for gifsicle fixes the following issues: Update to version 1.93: * Fix security bug on certain resize operations with `--resize-method=box` * Fix problems with colormapless GIFs. Update to version 1.92 * Add `--lossy` option from Kornel Lipi??ski. * Remove an assertion failure possible with `--conserve-memory` + `--colors` + `--careful`. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1249=1 - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2021-1249=1 - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-1249=1 - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2021-1249=1 Package List: - openSUSE Leap 15.2 (x86_64): gifsicle-1.93-lp152.5.3.1 gifsicle-debuginfo-1.93-lp152.5.3.1 gifsicle-debugsource-1.93-lp152.5.3.1 - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): gifsicle-1.93-bp153.2.3.1 gifsicle-debuginfo-1.93-bp153.2.3.1 gifsicle-debugsource-1.93-bp153.2.3.1 - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): gifsicle-1.93-bp152.4.3.1 gifsicle-debuginfo-1.93-bp152.4.3.1 gifsicle-debugsource-1.93-bp152.4.3.1 - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): gifsicle-1.93-bp151.4.3.1 References: . Update on gifsicle tackling resize vulnerabilities in openSUSE platforms; setup instructions provided.. openSUSE Update,gifsicle Security,Software Patch,Risk Management. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.