Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-5306

Опубликовано: 13 авг. 2024
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2024-5306: orc security update (MODERATE)

[0.4.28-4]

  • Add patch for CVE-2024-40897
  • Resolves: RHEL-50710

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

orc

0.4.28-4.el8_10

orc-compiler

0.4.28-4.el8_10

orc-devel

0.4.28-4.el8_10

Oracle Linux x86_64

orc

0.4.28-4.el8_10

orc-compiler

0.4.28-4.el8_10

orc-devel

0.4.28-4.el8_10

Связанные CVE

Связанные уязвимости

CVSS3: 6.7
ubuntu
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
redhat
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
nvd
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
msrc
4 месяца назад

Описание отсутствует

CVSS3: 6.7
debian
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC ...