Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 38 High Advisory: libcmis Memory Overrun - 2023-0d971cd6aa

fedora
Calendar Grey December 13, 2023
Dist Fedora Esm H88
Fedora 38 brings libcmis 0.6.2, addressing issues linked to poor input validation and improper macro handling.
7.5.9.2

Summary

LibCMIS is a C/C++ client library for working with CM (content management)

interfaces. The primary supported interface (which gave the library its

name) is CMIS, which allows applications to connect to any ECM behaving

as a CMIS server (Alfresco or Nuxeo are examples of open source ones).

Another supported interface is Google Drive.

Update Information:

7.5.9.2

Change Log

* Wed Nov 15 2023 Gwyn Ciesla - 0.6.2-1 - 0.6.2 * Mon Nov 13 2023 Gwyn Ciesla - 0.6.1-1 - 0.6.1 * Thu Oct 12 2023 Gwyn Ciesla - 0.6.0-1 - 0.6.0 * Thu Jul 20 2023 Fedora Release Engineering - 0.5.2-22 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Mon Feb 20 2023 Jonathan Wakely - 0.5.2-21 - Rebuilt for Boost 1.81

References


[ 1 ] Bug #2254004 - CVE-2023-6185 libreoffice: Improper Input Validation leading to arbitrary gstreamer plugin execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2254004 [ 2 ] Bug #2254006 - CVE-2023-6186 libreoffice: Insufficient macro permission validation leading to macro execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2254006

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0d971cd6aa' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libcmis
Product: Fedora 38
Version: 0.6.2
Release: 1.fc38
Summary: A C/C++ client library for CM interfaces

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here