-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEE2WgtvmwmcgaEBLlnCAvK1QvD6SAFAmWmoO4FAwAAAAAACgkQCAvK1QvD6SCI
zg/9G8sYk5BhZzrxCNZC4MavW4lk16NitDpGMf5X3otnkDrpaDURH7TEhOSi+IZ6QOLogogaoXcV
GyTmnhWxRHa+f/Ov4VAXO506x74fGsuz4ntNQZcSCa8g1ijPsZ8iNHG6wYOq3e8fhaDZo2qnExg2
Sh+xajHN7sjqCp8oJMGJpc/TGeMmT88jVt4NkEDAPRVspkHWMwV9AcNzmswg+XFe0qi2BwmTyz+d
KAZYta2FYczWfZq/kWrrrJlgWouB1x/U/SDwlppLEuKmBiMHsmw7LkHdLSdd7MeJdi1ZTbnoAPVc
pUDPTUKPZBOCL8jhmk9TbK6ybnwDP5M/7fe+ol9lh5HIo/B4Eu0TyZsDOYTYA2WynJZX5GU8Q62P
cYDsGo5LJqUVfY5x4mtlJ0jPD6LI5HR6fSbD4ODIk5dLy6+g1TjsSHqLw81fcksR2hqwgPbckqc9
8g9bfbum2IkVOrjJiV3Da1iyPPE06TBM5VIpDMONMAv/eSM9SzymYbFMG/gQ2ykF2nK0qWi7s+wK
aa0suZ7UViP+PLlwVeWQnvDVk/xt61dUVIzTxIbwmai1KosX8ijt2p3VXAE2cIt+5sKXM/VFagx/
Zey+UzdXkV+4sUdUNly9qX1fyNHSj79oq/VqeXGtUc4wVfqS+zIjzNib+imhVgrLIb7Xmm2cK41q
RMI=
=L+Oz
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6586-1
January 16, 2024
freeimage vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
- Ubuntu 14.04 LTS (Available with Ubuntu Pro)
Summary:
Several security issues were fixed in FreeImage.
Software Description:
- freeimage: Support library for graphics image formats
Details:
It was discovered that FreeImage incorrectly handled certain memory
operations. If a user were tricked into opening a crafted TIFF file, a
remote attacker could use this issue to cause a heap buffer overflow,
resulting in a denial of service attack. This issue only affected Ubuntu
16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12211)
It was discovered that FreeImage incorrectly processed images under
certain circumstances. If a user were tricked into opening a crafted TIFF
file, a remote attacker could possibly use this issue to cause a stack
exhaustion condition, resulting in a denial of service attack. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12213)
It was discovered that FreeImage incorrectly processed certain images.
If a user or automated system were tricked into opening a specially
crafted image file, a remote attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2020-21427,
CVE-2020-21428)
It was discovered that FreeImage incorrectly processed certain images.
If a user or automated system were tricked into opening a specially
crafted PFM file, an attacker could possibly use this issue to cause a
denial of service. (CVE-2020-22524)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
libfreeimage3 3.18.0+ds2-9.1ubuntu0.1
libfreeimageplus3 3.18.0+ds2-9.1ubuntu0.1
Ubuntu 23.04:
libfreeimage3 3.18.0+ds2-9ubuntu0.1
libfreeimageplus3 3.18.0+ds2-9ubuntu0.1
Ubuntu 22.04 LTS:
libfreeimage3 3.18.0+ds2-6ubuntu5.1
libfreeimageplus3 3.18.0+ds2-6ubuntu5.1
Ubuntu 20.04 LTS:
libfreeimage3 3.18.0+ds2-1ubuntu3.1
libfreeimageplus3 3.18.0+ds2-1ubuntu3.1
Ubuntu 18.04 LTS (Available with Ubuntu Pro):
libfreeimage3 3.17.0+ds1-5+deb9u1ubuntu0.1~esm1
libfreeimageplus3 3.17.0+ds1-5+deb9u1ubuntu0.1~esm1
Ubuntu 16.04 LTS (Available with Ubuntu Pro):
libfreeimage3 3.17.0+ds1-2ubuntu0.1+esm1
libfreeimageplus3 3.17.0+ds1-2ubuntu0.1+esm1
Ubuntu 14.04 LTS (Available with Ubuntu Pro):
libfreeimage3 3.15.4-3ubuntu0.1+esm3
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6586-1
CVE-2019-12211, CVE-2019-12213, CVE-2020-21427, CVE-2020-21428,
CVE-2020-22524
Package Information:
https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-9.1ubuntu0.1
https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-9ubuntu0.1
https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-6ubuntu5.1
https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-1ubuntu3.1
No comments:
Post a Comment