Security fix for CVE-2021-42715 and CVE-2021-42716. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-d1446cd1ac 2021-10-31 01:07:25.016970 --------------------------------------------------------------------------------Name : stb Product : Fedora 35 Version : 0 Release : 0.7.20211022gitaf1a5bc.fc35 URL : https://github.com/nothings/stb Summary : Single-file public domain libraries for C/C++ Description : Single-file public domain libraries for C/C++. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-42715 and CVE-2021-42716 --------------------------------------------------------------------------------ChangeLog: * Fri Oct 22 2021 Benjamin A. Beasley 0-0.7 - Security fix for CVE-2021-42715 and CVE-2021-42716 * Fri Oct 22 2021 Benjamin A. Beasley 0-0.6 - Update to af1a5bc * Fri Oct 22 2021 Benjamin A. Beasley 0-0.5 - Reduce macro indirection in the spec file --------------------------------------------------------------------------------References: [ 1 ] Bug #2017908 - CVE-2021-42715 stb: DoS in stb_image HDR loader via a crafted file https://bugzilla.redhat.com/show_bug.cgi?id=2017908 [ 2 ] Bug #2017913 - CVE-2021-42716 stb: heap-based buffer overflow in stb_image PNM loader https://bugzilla.redhat.com/show_bug.cgi?id=2017913 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-d1446cd1ac' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.