Advisories ยป MGASA-2015-0339

Updated freeimage packages fix security vulnerabilities

Publication date: 08 Sep 2015
Type: security
Affected Mageia releases : 4 , 5
CVE: CVE-2015-0852

Description

Updated freeimage packages fix security vulnerability:

FreeImage is vulnerable to an integer overflow in PluginPCX.cpp, making the
PCX loader vulnerable to malicious images with a bad window specification
(CVE-2015-0852).

Moreover, FreeImage was built in Mageia against a number of bundled libraries
with potential security vulnerabilities. Most of those dependencies were
unbundled to use the up-to-date system libraries, while the bundled libtiff
was updated to a more recent version.
                

References

SRPMS

4/core

5/core