Updated freeimage packages fix security vulnerabilities
Publication date: 08 Sep 2015Modification date: 08 Sep 2015
Type: security
Affected Mageia releases : 4 , 5
CVE: CVE-2015-0852
Description
Updated freeimage packages fix security vulnerability: FreeImage is vulnerable to an integer overflow in PluginPCX.cpp, making the PCX loader vulnerable to malicious images with a bad window specification (CVE-2015-0852). Moreover, FreeImage was built in Mageia against a number of bundled libraries with potential security vulnerabilities. Most of those dependencies were unbundled to use the up-to-date system libraries, while the bundled libtiff was updated to a more recent version.
References
SRPMS
5/core
- freeimage-3.154-1.1.mga5
4/core
- freeimage-3.154-1.1.mga4