Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 37: 2023-67d8bcb63c Critical Heap Overwrite Fix In Indent Software

fedora
Calendar Grey September 7, 2023
Dist Fedora Esm H88
Revise memory management errors in indentation, addressing severe vulnerabilities in the application.
This release fixes a heap buffer overwrite in search_brace() (CVE-2023-40305) and a heap overread in lexi().

Summary

Indent is a GNU program for beautifying C code, so that it is easier to

read. Indent can also convert from one C writing style to a different

one. Indent understands correct C syntax and tries to handle incorrect

C syntax.

Install the indent package if you are developing applications in C and

you want a program to format your code.

Update Information:

This release fixes a heap buffer overwrite in search_brace() (CVE-2023-40305) and a heap overread in lexi().

Change Log

* Wed Aug 16 2023 Petr Pisar - 2.2.13-4 - Fix a heap overread in search_brace/lexi - Fix CVE-2023-40305 (a heap buffer overwrite in search_brace) (bug #2231919) * Mon Apr 17 2023 Petr Pisar - 2.2.13-3 - Correct a license to "GPL-3.0-or-later AND BSD-3-Clause AND BSD-4.3TAHOE AND Latex2e-translated-notice"

References


[ 1 ] Bug #2231854 - CVE-2023-40305 indent: heap-based buffer overflow in search_brace() in indent.c https://bugzilla.redhat.com/show_bug.cgi?id=2231854

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-67d8bcb63c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: indent
Product: Fedora 37
Version: 2.2.13
Release: 4.fc37
URL:
Summary: A GNU program for formatting C code

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here