MGASA-2015-0339
Dashboard / Vulnerabilities / MGASA-2015-0339
Summary: Updated freeimage packages fix security vulnerabilities
Details: Updated freeimage packages fix security vulnerability: FreeImage is vulnerable to an integer overflow in PluginPCX.cpp, making the PCX loader vulnerable to malicious images with a bad window specification (CVE-2015-0852). Moreover, FreeImage was built in Mageia against a number of bundled libraries with potential security vulnerabilities. Most of those dependencies were unbundled to use the up-to-date system libraries, while the bundled libtiff was updated to a more recent version.
References: https://advisories.mageia.org/MGASA-2015-0339.html, https://bugs.mageia.org/show_bug.cgi?id=16662, http://openwall.com/lists/oss-security/2015/08/28/1
Affected packages
Package
Name: freeimage
Purl: pkg:rpm/mageia/freeimage?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
