Fedora 40: calibre 2024-a455bea9ca Security Advisory Updates
Summary
Calibre is meant to be a complete e-library solution. It includes library
management, format conversion, news feeds to ebook conversion as well as
e-book reader sync features.
Calibre is primarily a ebook cataloging program. It manages your ebook
collection for you. It is designed around the concept of the logical book,
i.e. a single entry in the database that may correspond to ebooks in several
formats. It also supports conversion to and from a dozen different ebook
formats.
Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ,
RTF, TXT, PDF and LRS.
Update Information:
Fix fonts for < f41 releases. Upgrade to latest upstream release to fix 4 CVE's and enable new hardware
Change Log
* Sun Aug 25 2024 Kevin Fenzi
References
[ 1 ] Bug #2303060 - CVE-2024-7009 calibre: From NVD collector [fedora-40]
https://bugzilla.redhat.com/show_bug.cgi?id=2303060
[ 2 ] Bug #2303063 - CVE-2024-7008 calibre: Unsanitized user-input in Calibre allow attackers to perform reflected cross-site scripting [fedora-40]
https://bugzilla.redhat.com/show_bug.cgi?id=2303063
[ 3 ] Bug #2303065 - CVE-2024-6782 calibre: Improper access control in Calibre allow unauthenticated attackers to achieve remote code execution. [fedora-40]
https://bugzilla.redhat.com/show_bug.cgi?id=2303065
[ 4 ] Bug #2303067 - CVE-2024-6781 calibre: Path traversal in Calibre allow unauthenticated attackers to achieve arbitrary file read. [fedora-40]
https://bugzilla.redhat.com/show_bug.cgi?id=2303067
[ 5 ] Bug #2307794 - Crash at start of "calibre"
https://bugzilla.redhat.com/show_bug.cgi?id=2307794
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a455bea9ca' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label