Описание
Security update for orc
This update for orc fixes the following issues:
- CVE-2024-40897: Fixed stack-based buffer overflow in the Orc compiler when formatting error messages for certain input files (bsc#1228184)
Список пакетов
Container containers/open-webui:0
liborc-0_4-0-0.4.28-150000.3.9.1
SUSE Enterprise Storage 7.1
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Linux Enterprise Micro 5.2
liborc-0_4-0-0.4.28-150000.3.9.1
SUSE Linux Enterprise Micro 5.3
liborc-0_4-0-0.4.28-150000.3.9.1
SUSE Linux Enterprise Micro 5.4
liborc-0_4-0-0.4.28-150000.3.9.1
SUSE Linux Enterprise Micro 5.5
liborc-0_4-0-0.4.28-150000.3.9.1
SUSE Linux Enterprise Module for Basesystem 15 SP6
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Linux Enterprise Module for Package Hub 15 SP6
liborc-0_4-0-32bit-0.4.28-150000.3.9.1
SUSE Linux Enterprise Server 15 SP3-LTSS
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Linux Enterprise Server 15 SP4-LTSS
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Linux Enterprise Server 15 SP5-LTSS
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Manager Proxy 4.3
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
SUSE Manager Server 4.3
liborc-0_4-0-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
openSUSE Leap 15.6
liborc-0_4-0-0.4.28-150000.3.9.1
liborc-0_4-0-32bit-0.4.28-150000.3.9.1
orc-0.4.28-150000.3.9.1
orc-doc-0.4.28-150000.3.9.1
Ссылки
- Link for SUSE-SU-2025:0344-1
- E-Mail link for SUSE-SU-2025:0344-1
- SUSE Security Ratings
- SUSE Bug 1228184
- SUSE CVE CVE-2024-40897 page
Описание
Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.
Затронутые продукты
Container containers/open-webui:0:liborc-0_4-0-0.4.28-150000.3.9.1
SUSE Enterprise Storage 7.1:liborc-0_4-0-0.4.28-150000.3.9.1
SUSE Enterprise Storage 7.1:orc-0.4.28-150000.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:liborc-0_4-0-0.4.28-150000.3.9.1
Ссылки
- CVE-2024-40897
- SUSE Bug 1228184