Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2024:0047-1

Опубликовано: 14 фев. 2024
Источник: suse-cvrf

Описание

Security update for hugin

This update for hugin fixes the following issues:

Update to version 2023.0.0:

  • PTBatcherGUI can now also queue user defined assistant and user defined output sequences.
  • PTBatcherGUI: Added option to generate panorama sequences from an existing pto template.
  • Assistant: Added option to select different output options like projection, FOV or canvas size depending on different variables (e.g. image count, field of view, lens type).
  • Allow building with epoxy instead of GLEW for OpenGL pointer management.
  • Several improvements to crop tool (outside crop, aspect ratio, ...).
  • Several bug fixes (e.g. in verdandi/internal blender).
  • Updated translations.
  • fixed: boo#1219819 (CVE-2024-25442), boo#1219820 (CVE-2024-25443) boo#1219821 (CVE-2024-25445), boo#1219822 (CVE-2024-25446)

Список пакетов

SUSE Package Hub 15 SP5
hugin-2023.0.0-bp155.2.3.1
openSUSE Leap 15.5
hugin-2023.0.0-bp155.2.3.1

Описание

An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.


Затронутые продукты
SUSE Package Hub 15 SP5:hugin-2023.0.0-bp155.2.3.1
openSUSE Leap 15.5:hugin-2023.0.0-bp155.2.3.1

Ссылки

Описание

An issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via parsing a crafted image.


Затронутые продукты
SUSE Package Hub 15 SP5:hugin-2023.0.0-bp155.2.3.1
openSUSE Leap 15.5:hugin-2023.0.0-bp155.2.3.1

Ссылки

Описание

Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.


Затронутые продукты
SUSE Package Hub 15 SP5:hugin-2023.0.0-bp155.2.3.1
openSUSE Leap 15.5:hugin-2023.0.0-bp155.2.3.1

Ссылки

Описание

An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.


Затронутые продукты
SUSE Package Hub 15 SP5:hugin-2023.0.0-bp155.2.3.1
openSUSE Leap 15.5:hugin-2023.0.0-bp155.2.3.1

Ссылки
Уязвимость openSUSE-SU-2024:0047-1