Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Fedora 38: FEDORA-2023-c1318fb7f8 Moderate: Kingpin Cache Poisoning

fedora
Calendar Grey September 21, 2023
Scroller Fedora
Patch released for golang-gopkg-alecthomas-kingpin-2 in Fedora 38 tackling severe cache compromise vulnerability.
notes=Security fix for CVE-2022-46146, update to v0.10.0

Summary

Kingpin is a fluent-style, type-safe command-line parser. It supports flags,

nested commands, and positional arguments.

Update Information:

notes=Security fix for CVE-2022-46146, update to v0.10.0

Change Log

References


[ 1 ] Bug #2149436 - CVE-2022-46146 exporter-toolkit: authentication bypass via cache poisoning https://bugzilla.redhat.com/show_bug.cgi?id=2149436

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-c1318fb7f8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
important
Lowest
Low
Medium
High
Critical

Name: golang-gopkg-alecthomas-kingpin-2
Product: Fedora 38
Version: 2.3.2
Release: 1.fc38
Summary: Go command line and flag parser

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.