LibRaw-0.19.5-4.el8

エラータID: AXSA:2024-8196:03

Release date: 
Friday, June 14, 2024 - 23:28
Subject: 
LibRaw-0.19.5-4.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

LibRaw is a library for reading RAW files obtained from digital photo cameras (CRW/CR2, NEF, RAF, DNG, and others).

Security Fix(es):

* LibRaw: stack buffer overflow in LibRaw_buffer_datastream::gets() in src/libraw_datastream.cpp (CVE-2021-32142)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 8.10 Release Notes linked from the References section.

CVE-2021-32142
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. LibRaw-0.19.5-4.el8.src.rpm
    MD5: 3e798778270344714183fe580d5479c9
    SHA-256: 99184b1c32fd7e36081057a62a0301e42625c4bff27a92894569f1bc5881b119
    Size: 1.26 MB

Asianux Server 8 for x86_64
  1. LibRaw-0.19.5-4.el8.i686.rpm
    MD5: fba88ae20830a4a75f496f1b1d1ae786
    SHA-256: 8ecb0eeb25a0905fd2b4385949edb2969eaf1520f91fc75f1e4b42e36f50914c
    Size: 336.21 kB
  2. LibRaw-0.19.5-4.el8.x86_64.rpm
    MD5: 758da871e706f2d3d0b209afbfbadfd5
    SHA-256: 515c2f04bf5caba9dfec12611adb4563f5d534d6ca2a9ba25368b0bab1554f25
    Size: 314.98 kB
  3. LibRaw-devel-0.19.5-4.el8.i686.rpm
    MD5: eb9b2bfbc8e29f0391f9ff70ebf6e5fc
    SHA-256: bbae53aba861d92c0166f3ba4322d5ea977d3ffd5c26f1b8048ab1b786a0b196
    Size: 88.36 kB
  4. LibRaw-devel-0.19.5-4.el8.x86_64.rpm
    MD5: 968309596bca4e16b3948f3fadb1e009
    SHA-256: f94476b046fc3e8cf7708500b23b7de2736f227e39dcf3a4d7584c788399655d
    Size: 88.35 kB