An issue has been found in shapelib, a library for reading and writing ESRI Shapefiles. The issue is related to a double free, which results in a crash and a denial of service. For Debian 11 bullseye, this problem has been fixed in version. Debian LTS Advisory DLA-4451-1
Backport fix for CVE-2022-0699.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-216f0a205a 2022-03-26 14:56:28.653031 --------------------------------------------------------------------------------Name : shapelib Product : Fedora 36 Version : 1.5.0 Release : 12.fc36 URL : http://shapelib.maptools.org/ Summary : C library for handling ESRI Shapefiles Description : The Shapefile C Library provides the ability to write simple C programs for reading, writing and updating (to a limited extent) ESRI Shapefiles, and the associated attribute file (.dbf). --------------------------------------------------------------------------------Update Information: Backport fix for CVE-2022-0699. --------------------------------------------------------------------------------ChangeLog: * Wed Mar 2 2022 Sandro Mani - 1.5.0-12 - Backport fix for CVE-2022-0699 --------------------------------------------------------------------------------References: [ 1 ] Bug #2054307 - CVE-2022-0699 shapelib: Double-free vulnerability in contrib/shpsort.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2054307 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-216f0a205a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Add mingw subpackages.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-6746739d52 2022-03-26 14:56:28.650826 --------------------------------------------------------------------------------Name : shapelib Product : Fedora 36 Version : 1.5.0 Release : 11.fc36 URL : http://shapelib.maptools.org/ Summary : C library for handling ESRI Shapefiles Description : The Shapefile C Library provides the ability to write simple C programs for reading, writing and updating (to a limited extent) ESRI Shapefiles, and the associated attribute file (.dbf). --------------------------------------------------------------------------------Update Information: Add mingw subpackages. --------------------------------------------------------------------------------ChangeLog: * Thu Feb 24 2022 Sandro Mani - 1.5.0-11 - Make mingw subpackages noarch * Thu Feb 24 2022 Sandro Mani - 1.5.0-10 - Make mingw subpackages noarch * Thu Feb 24 2022 Sandro Mani - 1.5.0-9 - Add mingw subpackage --------------------------------------------------------------------------------References: [ 1 ] Bug #2060171 - F36FailsToInstall: mingw64-freeimage, mingw32-freeimage https://bugzilla.redhat.com/show_bug.cgi?id=2060171 [ 2 ] Bug #2060172 - F36FailsToInstall: mingw32-gdal, mingw64-gdal https://bugzilla.redhat.com/show_bug.cgi?id=2060172 [ 3 ] Bug #2060174 - F36FailsToInstall: mingw32-opencv, mingw64-opencv https://bugzilla.redhat.com/show_bug.cgi?id=2060174 [ 4 ] Bug #2060175 - F36FailsToInstall: mingw32-poppler, mingw64-poppler https://bugzilla.redhat.com/show_bug.cgi?id=2060175 [ 5 ] Bug #2060176 - F36FailsToInstall: mingw32-python3-shapely, mingw64-python3-shapely https://bugzilla.redhat.com/show_bug.cgi?id=2060176 [ 6 ] Bug #2060177 - F36FailsToInstall: mingw32-qtspell-qt5, mingw64-qtspell-qt5 https://bugzilla.redhat.com/show_bug.cgi?id=2060177 [ 7 ] Bug #2060358 - F36FailsToInstall: mingw32-python3-pyproj, mingw64-python3-pyproj https://bugzilla.redhat.com/show_bug.cgi?id=2060358 [ 8 ] Bug #2060816 - F36FailsToInstall: mingw64-SDL2_image, mingw32-SDL2_image https://bugzilla.redhat.com/show_bug.cgi?id=2060816 [ 9 ] Bug #2060818 - F36FailsToInstall: mingw32-qt5-qtimageformats, mingw64-qt5-qtimageformats https://bugzilla.redhat.com/show_bug.cgi?id=2060818 [ 10 ] Bug #2060819 - F36FailsToInstall: mingw32-qt5-qtwebkit, mingw64-qt5-qtwebkit https://bugzilla.redhat.com/show_bug.cgi?id=2060819 [ 11 ] Bug #2060820 - F36FailsToInstall: mingw32-qt6-qtimageformats, mingw64-qt6-qtimageformats https://bugzilla.redhat.com/show_bug.cgi?id=2060820 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-6746739d52' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Double-free vulnerability in contrib/shpsort.c. (CVE-2022-0699) References: - https://bugs.mageia.org/show_bug.cgi?id=30114 - . MGASA-2022-0096 - Updated shapelib packages fix security vulnerability Publication date: 11 Mar 2022 URL: https://advisories.mageia.org/MGASA-2022-0096.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-0699 Double-free vulnerability in contrib/shpsort.c. (CVE-2022-0699) References: - https://bugs.mageia.org/show_bug.cgi?id=30114 - - https://www.cve.org/CVERecord?id=CVE-2022-0699 SRPMS: - 8/core/shapelib-1.5.0-2.1.mga8 . The recent shapelib package updates address a significant double-free vulnerability within Mageia. This announcement includes specifics and pertinent links.. shapelib security update, mageia vulnerability, double-free error, security advisory, software patch. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for shapelib ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:0068-1 Rating: important References: #1196236 Cross-References: CVE-2022-0699 Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for shapelib fixes the following issues: - CVE-2022-0699: Fixed a Double-free vulnerability in contrib/shpsort.c Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-68=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): libshp-devel-1.5.0-bp153.2.3.1 libshp2-1.5.0-bp153.2.3.1 shapelib-1.5.0-bp153.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-0699.html https://bugzilla.suse.com/1196236 . Resolution implemented for key Shapelib enhancement, targeting a significant flaw present in the openSUSE Backports distribution.. openSUSE Security Update, shapelib Patch, Double-free Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.