Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 30: FEDORA-2019-2a16e1ab93 critical: cutter radare2 Security Fixes

fedora
Calendar Grey July 29, 2019
Dist Fedora Esm H88
Fedora 30's new update tackles vulnerabilities in cutter, effectively patching significant security weaknesses linked to radare2.
Rebase to radare2 3.6.0 and fix CVE-2019-12790, CVE-2019-12802 and CVE-2019-12865 and rebase cutter to 1.8.3.

Summary

Cutter is a Qt and C++ GUI for radare2. Its goal is making an advanced,

customizable and FOSS reverse-engineering platform while keeping the user

experience at mind. Cutter is created by reverse engineers for reverse

engineers.

Rebase to radare2 3.6.0 and fix CVE-2019-12790, CVE-2019-12802 and

CVE-2019-12865 and rebase cutter to 1.8.3.

* Mon Jul 15 2019 Riccardo Schirone - 1.8.3-1

- rebase to cutter 1.8.3

* Wed Jun 26 2019 Riccardo Schirone - 1.8.0-4

- recompile for radare2 3.6.0

* Mon Apr 15 2019 Riccardo Schirone - 1.8.0-3

- recompile for radare2 3.4.1

* Tue Apr 9 2019 Lubomir Rintel - 1.8.0-2

- Update to radare2 3.4.1

[ 1 ] Bug #1725676 - CVE-2019-12865 radare2: double free in cmd_mount in libr/core/cmd_mount.c [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1725676

[ 2 ] Bug #1722733 - CVE-2019-12802 radare2: denial of service in function rcc_context in /libr/egg/egg_lang.c [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1722733

[ 3 ] Bug #1723354 - CVE-2019-12790 radare2: heap-based buffer over-read in function r_egg_lang_parsechar in egg_lang.c [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1723354

su -c 'dnf upgrade --advisory FEDORA-2019-2a16e1ab93' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 30
Version: 1.8.3
Release: 1.fc30
Summary: GUI for radare2 reverse engineering framework

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here