Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in CImg
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in CImg
ID: FEDORA-2018-4c9e9b82d1
Distribution: Fedora
Plattformen: Fedora 29
Datum: Fr, 5. Oktober 2018, 23:11
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7637
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7638
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7588
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7641
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7639
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7589
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7640
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7587
Applikationen: CImg

Originalnachricht

-------------------------------------------------------------------------------
-
Fedora Update Notification
FEDORA-2018-4c9e9b82d1
2018-10-05 16:00:25.666956
-------------------------------------------------------------------------------
-

Name : CImg
Product : Fedora 29
Version : 2.3.6
Release : 1.fc29
URL : https://github.com/dtschump/CImg
Summary : C++ Template Image Processing Toolkit
Description :
The CImg Library is an open-source C++ toolkit for image processing.
It consists in a single header file 'CImg.h' providing a minimal set of
C++
classes and methods that can be used in your own sources, to load/save,
process and display images. Very portable, efficient and easy to use,
it's a pleasant library for developping image processing algorithms in C++.

-------------------------------------------------------------------------------
-
Update Information:

Update to 2.3.6 release. Fixes CVE-2018-7587, CVE-2018-7588, CVE-2018-7589,
CVE-2018-7637, CVE-2018-7638, CVE-2018-7639, CVE-2018-7640, CVE-2018-7641
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1552294 - CVE-2018-7587 CImg: Denial of Service (DoS) via crafted
BMP image
https://bugzilla.redhat.com/show_bug.cgi?id=1552294
[ 2 ] Bug #1552296 - CVE-2018-7588 CImg: heap-based buffer over-read via
crafted BMP image in load_bmp in CImg.h
https://bugzilla.redhat.com/show_bug.cgi?id=1552296
[ 3 ] Bug #1552299 - CVE-2018-7589 CImg: double free via crafted BMP image in
load_bmp in CImg.h
https://bugzilla.redhat.com/show_bug.cgi?id=1552299
[ 4 ] Bug #1552920 - CVE-2018-7637 CImg: heap-based buffer over-read in
load_bmp in CImg.h via crafted bmp image (16 colors)
https://bugzilla.redhat.com/show_bug.cgi?id=1552920
[ 5 ] Bug #1552919 - CVE-2018-7638 CImg: heap-based buffer over-read in
load_bmp in CImg.h via crafted bmp image (256 colors)
https://bugzilla.redhat.com/show_bug.cgi?id=1552919
[ 6 ] Bug #1552917 - CVE-2018-7639 CImg: heap-based buffer over-read in
load_bmp in CImg.h via crafted bmp image (16 bits colors)
https://bugzilla.redhat.com/show_bug.cgi?id=1552917
[ 7 ] Bug #1552918 - CVE-2018-7640 CImg: heap-based buffer over-read in
load_bmp in CImg.h via crafted bmp image (monochrome)
https://bugzilla.redhat.com/show_bug.cgi?id=1552918
[ 8 ] Bug #1552916 - CVE-2018-7641 CImg: heap-based buffer over-read in
load_bmp in CImg.h via crafted bmp image (32 bits colors)
https://bugzilla.redhat.com/show_bug.cgi?id=1552916
-------------------------------------------------------------------------------
-

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-4c9e9b82d1' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Pro-Linux
Unterstützer werden
Neue Nachrichten
Werbung