An out of bounds read in function QRadialFetchSimd from crafted svg file may lead to information disclosure or other potential consequences. This update includes the backported upstream fix and should resolve the security issue.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-a95a40b78b 2021-03-25 00:15:39.359217 --------------------------------------------------------------------------------Name : qt5-qtsvg Product : Fedora 34 Version : 5.15.2 Release : 4.fc34 URL : https://www.qt.io/ Summary : Qt5 - Support for rendering and displaying SVG Description : Scalable Vector Graphics (SVG) is an XML-based language for describing two-dimensional vector graphics. Qt provides classes for rendering and displaying SVG drawings in widgets and on other paint devices. --------------------------------------------------------------------------------Update Information: An out of bounds read in function QRadialFetchSimd from crafted svg file may lead to information disclosure or other potential consequences. This update includes the backported upstream fix and should resolve the security issue. --------------------------------------------------------------------------------ChangeLog: * Tue Mar 9 2021 Than Ngo - 5.15.2-4 - Resolves: #1931447, Out of bounds read in function QRadialFetchSimd from crafted svg file --------------------------------------------------------------------------------References: [ 1 ] Bug #1931444 - qt: Out of bounds read in function QRadialFetchSimd from crafted svg file https://bugzilla.redhat.com/show_bug.cgi?id=1931444 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-a95a40b78b' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2015-0250. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-8783 2015-05-25 20:39:36 -------------------------------------------------------------------------------- Name : batik Product : Fedora 21 Version : 1.8 Release : 0.18.svn1230816.fc21 URL : https://xmlgraphics.apache.org/batik/ Summary : Scalable Vector Graphics for Java Description : Batik is a Java(tm) technology based toolkit for applications that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-0250 -------------------------------------------------------------------------------- ChangeLog: * Thu May 21 2015 Michal Srb - 1.8-0.18.svn1230816 - Disable external xml entities - Resolves: CVE-2015-0250 * Mon Jan 12 2015 Alexander Kurtakov 1.8-0.17.svn1230816 - Add obsoletes in batik-css to ease updates. * Mon Dec 8 2014 Alexander Kurtakov 1.8-0.16.svn1230816 - Split css in subpackage. -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update batik' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Improperly sanitised data in Dia allows remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200510-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Dia: Arbitrary code execution through SVG import Date: October 06, 2005 Bugs: #107916 ID: 200510-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Improperly sanitised data in Dia allows remote attackers to execute arbitrary code. Background ========= Dia is a gtk+ based diagram creation program released under the GPL license. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-office/dia < 0.94-r3 > = 0.94-r3 Description ========== Joxean Koret discovered that the SVG import plugin in Dia fails to properly sanitise data read from an SVG file. Impact ===== An attacker could create a specially crafted SVG file, which, when imported into Dia, could lead to the execution of arbitrary code. Workaround ========= There is no known workaround at this time. Resolution ========= All Dia users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-office/dia-0.94-r3" References ========= [ 1 ] CAN-2005-2966 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200510-06 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our usersmachines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.