Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-40897

Опубликовано: 26 июл. 2024
Источник: redhat
CVSS3: 6.7

Описание

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7orcOut of support scope
Red Hat Enterprise Linux 8orcFixedRHSA-2024:530613.08.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportorcFixedRHSA-2024:588227.08.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportorcFixedRHSA-2024:615903.09.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceorcFixedRHSA-2024:615903.09.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsorcFixedRHSA-2024:615903.09.2024
Red Hat Enterprise Linux 9orcFixedRHSA-2024:618403.09.2024
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsorcFixedRHSA-2024:562920.08.2024
Red Hat Enterprise Linux 9.2 Extended Update SupportorcFixedRHSA-2024:563820.08.2024

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2300010orc: Stack-based buffer overflow vulnerability in ORC

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
nvd
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
msrc
4 месяца назад

Описание отсутствует

CVSS3: 6.7
debian
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC ...

suse-cvrf
5 месяцев назад

Security update for orc

6.7 Medium

CVSS3