SECURITY: cfitsio security alert
Ole Streicher wrote on Mar 09, 2018
Hi,
a new version of cfitsio just came out, accompanied with the following notice from upstream:
The NASA security team requires the following warning to all users of CFITSIO:
The CFITSIO open source software project contains vulnerabilities that could allow a remote, unauthenticated attacker to take control of a server running the CFITSIO software. These vulnerabilities affect all servers and products running the CFITSIO software.
The CFITSIO team has released software updates to address these vulnerabilities. There are no workarounds to address these vulnerabilities. In all cases, the CFITSIO team is recommending an immediate update to resolve the issues.
The current IRAF binary packages for MacOS and Linux contain a statically linked version of an old cfitsio version (3.31), which is likely affected by this problem. It therefore may be wise to release a new IRAF binary version using the new version (3.43) ASAP.
The Debian and Ubuntu IRAF packages are not directly affected, since they dynamically link to cfitsio. I also created Debian bug #892458, which shall result in the upload of a fixed package (please ensure that you get this update). For the Astroconda package, I don't know the details.
To trace the solution of the bug, I also created issue #134 in the github repository.
Best regards
Ole
Ole Streicher wrote on Mar 09, 2018
Just for completeness: FITSUTIL is also affected, since it comes with its own cfitsion sources (3.37), which are as well statically linked. Issue #3.
If other external packages use cfitsio from IRAF, they should be relinked as well after IRAF upgraded.
Last post on Mar 09, 2018