Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Ubuntu 22.04: 2023-a5e67d10fc Critical: NetworkManager Security Patch

fedora
Calendar Grey September 13, 2023
Dist Fedora Esm H88
Update libeconf to version 0.5.2 to resolve severe bugs and improve configuration handling in Fedora 37.
Rebase to 0.5.2 to fix CVE-2023-22652 and CVE-2023-30079

Summary

libeconf is a highly flexible and configurable library to parse and manage

key=value configuration files. It reads configuration file snippets from

different directories and builds the final configuration file from it.

Update Information:

Rebase to 0.5.2 to fix CVE-2023-22652 and CVE-2023-30079

Change Log

* Mon Aug 28 2023 Iker Pedrosa - 0.5.2-1 - Update to 0.5.2 (RH#1980774) - Fix CVE-2023-22652 (RH#2212464) - Fix CVE-2023-30079 (RH#2235236) * Thu Jul 20 2023 Fedora Release Engineering - 0.4.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Jan 19 2023 Fedora Release Engineering - 0.4.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild

References


[ 1 ] Bug #1980774 - libeconf-0.5.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1980774 [ 2 ] Bug #2212464 - CVE-2023-22652 libeconf: stack-based buffer overflow in read_file() in lib/getfilecontents.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2212464 [ 3 ] Bug #2235236 - CVE-2023-30079 libeconf: Stack overflow in function read_file at atlibeconf/lib/getfilecontents.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2235236

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-b4b77f950c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libeconf
Product: Fedora 37
Version: 0.5.2
Release: 1.fc37
Summary: Enhanced config file parser library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here