Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:5306

Опубликовано: 07 мая 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: orc security update

Orc is a library and set of tools for compiling and executing very simple programs that operate on arrays of data. The "language" is a generic assembly language that represents many of the features available in SIMD architectures, including saturated addition and subtraction, and many arithmetic operations.

Security Fix(es):

  • orc: Stack-based buffer overflow vulnerability in ORC (CVE-2024-40897)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
orcx86_644.el8_10orc-0.4.28-4.el8_10.x86_64.rpm
orc-compilerx86_644.el8_10orc-compiler-0.4.28-4.el8_10.x86_64.rpm
orc-develx86_644.el8_10orc-devel-0.4.28-4.el8_10.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 6.7
ubuntu
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
redhat
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
nvd
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
msrc
4 месяца назад

Описание отсутствует

CVSS3: 6.7
debian
11 месяцев назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC ...