Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:2663-1

Опубликовано: 30 июл. 2024
Источник: suse-cvrf

Описание

Security update for orc

This update for orc fixes the following issues:

  • CVE-2024-40897: Fixed stack-based buffer overflow in the orc compiler when formatting error messages for certain input files (bsc#1228184)

Список пакетов

Container containers/open-webui:0
liborc-0_4-0-0.4.28-150000.3.6.1
SUSE Enterprise Storage 7.1
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Linux Enterprise Micro 5.2
liborc-0_4-0-0.4.28-150000.3.6.1
SUSE Linux Enterprise Micro 5.3
liborc-0_4-0-0.4.28-150000.3.6.1
SUSE Linux Enterprise Micro 5.4
liborc-0_4-0-0.4.28-150000.3.6.1
SUSE Linux Enterprise Micro 5.5
liborc-0_4-0-0.4.28-150000.3.6.1
SUSE Linux Enterprise Module for Basesystem 15 SP5
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Linux Enterprise Module for Basesystem 15 SP6
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP5
liborc-0_4-0-32bit-0.4.28-150000.3.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP6
liborc-0_4-0-32bit-0.4.28-150000.3.6.1
SUSE Linux Enterprise Server 15 SP2-LTSS
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Linux Enterprise Server 15 SP3-LTSS
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Linux Enterprise Server 15 SP4-LTSS
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Manager Proxy 4.3
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
SUSE Manager Server 4.3
liborc-0_4-0-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
openSUSE Leap 15.5
liborc-0_4-0-0.4.28-150000.3.6.1
liborc-0_4-0-32bit-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
orc-doc-0.4.28-150000.3.6.1
openSUSE Leap 15.6
liborc-0_4-0-0.4.28-150000.3.6.1
liborc-0_4-0-32bit-0.4.28-150000.3.6.1
orc-0.4.28-150000.3.6.1
orc-doc-0.4.28-150000.3.6.1
openSUSE Leap Micro 5.5
liborc-0_4-0-0.4.28-150000.3.6.1

Описание

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.


Затронутые продукты
Container containers/open-webui:0:liborc-0_4-0-0.4.28-150000.3.6.1
SUSE Enterprise Storage 7.1:liborc-0_4-0-0.4.28-150000.3.6.1
SUSE Enterprise Storage 7.1:orc-0.4.28-150000.3.6.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:liborc-0_4-0-0.4.28-150000.3.6.1

Ссылки