2019-12-18
ALT-BU-2019-4134-3
Branch sisyphus update bulletin.
Closed vulnerabilities
Published: 2025-01-29
BDU:2025-00841
Уязвимость компонента modules/loaders/loader_ico.c библиотеки обработки изображений Imlib2 позволяющая нарушителю вызвать отказ в обслуживании
Severity: CRITICAL (9.1)Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Severity: MEDIUM (6.4)Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P
References:
Published: 2020-05-09
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2020-12761
modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map.
Severity: MEDIUM (6.4)Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P
Severity: CRITICAL (9.1)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
References:
Package python-module-Enable updated to version 4.8.0-alt2 for branch sisyphus in task 242822.
Closed bugs
python-module-Enable-4.6.1-alt1 builds and provides a bundled copy of libfreetype
Closed bugs
Закончить перевод TuxMath
