autotrace-0.31.1-55.el8

エラータID: AXSA:2023-5902:02

Release date: 
Wednesday, June 7, 2023 - 12:22
Subject: 
autotrace-0.31.1-55.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

AutoTrace is a program for converting bitmaps to vector graphics.

Security Fix(es):

* autotrace: heap-buffer overflow via the ReadImage() at input-bmp.c (CVE-2022-32323)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 8.8 Release Notes linked from the References section.

CVE-2022-32323
AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. autotrace-0.31.1-55.el8.src.rpm
    MD5: 0136b5e90a667a82161f13d1c6a40bbf
    SHA-256: 6ad2d4b06fbb05cbaa0b4973380d5286a0eebc7835b17f8708296cfde44c06a8
    Size: 377.05 kB

Asianux Server 8 for x86_64
  1. autotrace-0.31.1-55.el8.i686.rpm
    MD5: 6f2e73970d431c5df9255698752d8760
    SHA-256: 98f98d8de1fed688cd24eef5912c1a63699ec44f6919dbb9581848c01cc1fb67
    Size: 152.61 kB
  2. autotrace-0.31.1-55.el8.x86_64.rpm
    MD5: 9efaabfedb7fc05da2ab90f62fc56f04
    SHA-256: 94de84a91f91062cf6712aab60ec337aa6974bb1774bf9ca3af1d0f207c4225e
    Size: 146.62 kB