Skip to content

Security: please update cfitsio #7272

@olebole

Description

@olebole

A new version of cfitsio just came out, accompanied with the following notice from upstream:

The NASA security team requires the following warning to all users of CFITSIO:

The CFITSIO open source software project contains vulnerabilities that could allow a remote, unauthenticated attacker to take control of a server running the CFITSIO software. These vulnerabilities affect all servers and products running the CFITSIO software.
The CFITSIO team has released software updates to address these vulnerabilities. There are no workarounds to address these vulnerabilities. In all cases, the CFITSIO team is recommending an immediate update to resolve the issues.

It is still unclear what the exact problem is (see discussion in Debian bug #892458), but it may be wise to update cfitsio in 3.X and 2.X and to create a new point release.

Metadata

Metadata

Assignees

Labels

🔥CriticalexternalPRs and issues related to external packages vendored with Astropy (astropy.extern)io.fits

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions