Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Warning: Undefined array key "Description" in /var/www/www.linuxsecurity.com-443/html/lsadvisories/lsadvisories.php on line 220

Fedora 38: FEDORA-2023-3589ad1c55 Critical: bzip3 Memory Heap Issue

fedora
Calendar Grey April 15, 2023
Dist Fedora Esm H88
Fedora System Alert FEDORA-2023-78b9de2f0e fixes critical buffer overflow in tar utility.
This release fixes a memory heap corruption.

Summary

These are tools for compressing, decompressing, printing, and searching bzip3

files. bzip3 features higher compression ratios and better performance than

bzip2 thanks to an order-0 context mixing entropy coder, a fast

Burrows-Wheeler transform code making use of suffix arrays and a run-length

encoding with Lempel-Ziv prediction pass based on LZ77-style string matching

and PPM-style context modeling.

This release fixes a memory heap corruption.

* Wed Apr 5 2023 Petr Pisar - 1.3.0-1

- 1.3.0 bump

[ 1 ] Bug #2185019 - CVE-2023-29415 CVE-2023-29416 CVE-2023-29417 CVE-2023-29418 CVE-2023-29419 CVE-2023-29420 CVE-2023-29421 bzip3: Multiple vulnerabilities

https://bugzilla.redhat.com/show_bug.cgi?id=2185019

su -c 'dnf upgrade --advisory FEDORA-2023-3589ad1c55' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 38
Version: 1.3.0
Release: 1.fc38
Summary: Tools for compressing and decompressing bzip3 files

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here