Mageia alert MGASA-2017-0351 (libwmf)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2017-0351: Updated libwmf packages fix security vulnerability | |
| Date: | Thu, 21 Sep 2017 15:44:12 +0200 | |
| Message-ID: | <20170921134412.C8C519F88E@duvel.mageia.org> |
MGASA-2017-0351 - Updated libwmf packages fix security vulnerability Publication date: 21 Sep 2017 URL: https://advisories.mageia.org/MGASA-2017-0351.html Type: security Affected Mageia releases: 5, 6 CVE: CVE-2017-6362 Description: Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors. (CVE-2017-6362) References: - https://bugs.mageia.org/show_bug.cgi?id=21707 - https://lists.fedoraproject.org/archives/list/package-ann... - http://pkgs.fedoraproject.org/cgit/rpms/libwmf.git/commit... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6362 SRPMS: - 6/core/libwmf-0.2.8.4-37.1.mga6 - 5/core/libwmf-0.2.8.4-32.5.mga5
