|
|
Log in / Subscribe / Register

Mageia alert MGASA-2017-0223 (libraw)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2017-0223: Updated libraw packages fix security vulnerabilities
Date:  Fri, 28 Jul 2017 20:12:57 +0200
Message-ID:  <20170728181257.4C09C9F88C@duvel.mageia.org>

MGASA-2017-0223 - Updated libraw packages fix security vulnerabilities Publication date: 28 Jul 2017 URL: http://advisories.mageia.org/MGASA-2017-0223.html Type: security Affected Mageia releases: 5 CVE: CVE-2017-6886, CVE-2017-6887, CVE-2017-6889, CVE-2017-6890 Description: A memory corruption in parse_tiff_ifd() function (CVE-2017-6886). A memory corruption via e.g. a specially crafted KDC file parse_tiff_ifd() (CVE-2017-6887). An integer overflow error within the "foveon_load_camf()" function (CVE-2017-6889). A boundary error within the "foveon_load_camf()" function (CVE-2017-6890). References: - https://bugs.mageia.org/show_bug.cgi?id=21004 - https://lists.opensuse.org/opensuse-updates/2017-05/msg00... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6886 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6887 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6889 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6890 SRPMS: - 5/core/libraw-0.16.2-1.2.mga5


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds