radare2-5.8.8-2.fc37

Read Time:14 Second

FEDORA-2023-f2a6d27239

Packages in this update:

radare2-5.8.8-2.fc37

Update description:

cherrypick from upstream master patches for known vulnerabilities:
CVE-2023-4322 – heap-buffer-overflow in the brainfuck dissassembler
CVE-2023-5686 – heap-buffer-overflow in /radare2/shlr/java/code.c

Read More

radare2-5.8.8-2.el7

Read Time:14 Second

FEDORA-EPEL-2023-87285c6aca

Packages in this update:

radare2-5.8.8-2.el7

Update description:

cherrypick from upstream master patches for known vulnerabilities:
CVE-2023-4322 – heap-buffer-overflow in the brainfuck dissassembler
CVE-2023-5686 – heap-buffer-overflow in /radare2/shlr/java/code.c

Read More

radare2-5.8.8-2.el9

Read Time:14 Second

FEDORA-EPEL-2023-1c3e19a13a

Packages in this update:

radare2-5.8.8-2.el9

Update description:

cherrypick from upstream master patches for known vulnerabilities:
CVE-2023-4322 – heap-buffer-overflow in the brainfuck dissassembler
CVE-2023-5686 – heap-buffer-overflow in /radare2/shlr/java/code.c

Read More

radare2-5.8.8-2.el8

Read Time:14 Second

FEDORA-EPEL-2023-63d2fd37d2

Packages in this update:

radare2-5.8.8-2.el8

Update description:

cherrypick from upstream master patches for known vulnerabilities:
CVE-2023-4322 – heap-buffer-overflow in the brainfuck dissassembler
CVE-2023-5686 – heap-buffer-overflow in /radare2/shlr/java/code.c

Read More

DSA-5547-1 pmix – security update

Read Time:22 Second

Francois Diakhate reported that a race condition in pmix, a library
implementing Process Management Interface (PMI) Exascale API, could
allow a malicious user to obtain ownership of an arbitrary file on the
filesystem when parts of the PMIx library are called by a process with
elevated privileges, resulting in privilege escalation. This may
happen under the default configuration of certain workload managers,
including Slurm.

https://security-tracker.debian.org/tracker/DSA-5547-1

Read More

DSA-5547 pmix – security update

Read Time:19 Second

Francois Diakhate reported that a race condition in pmix, a library
implementing Process Management Interface (PMI) Exascale API, could
allow a malicious user to obtain ownership of an arbitrary file on the
filesystem when parts of the PMIx library are called by a process with
elevated privileges, resulting in privilege escalation. This may
happen under the default configuration of certain workload managers,
including Slurm.

Read More