Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 38: 2023-27ec59a486 Moderate: picocli DoS Threat

fedora
Calendar Grey July 6, 2023
Dist Fedora Esm H88
Crucial announcement regarding picocli version 4.7.4 that tackles vulnerabilities and mitigates risks of stack overflow.
Update to version 4.7.4 Security fix for CVE-2022-41854

Summary

Picocli is a modern library and framework, written in Java, that contains both

an annotations API and a programmatic API. It features usage help with ANSI

colors and styles, TAB auto-completion and nested sub-commands. In a single

file, so you can include it in source form. This lets users run picocli-based

applications without requiring picocli as an external dependency.

Update to version 4.7.4 Security fix for CVE-2022-41854

* Mon Jun 26 2023 Didik Supriadi - 4.7.4-1

- Update to version 4.7.4

[ 1 ] Bug #2151988 - CVE-2022-41854 dev-java/snakeyaml: DoS via stack overflow

https://bugzilla.redhat.com/show_bug.cgi?id=2151988

su -c 'dnf upgrade --advisory FEDORA-2023-27ec59a486' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Product: Fedora 38
Version: 4.7.4
Release: 1.fc38
Summary: Java command line parser with both an annotations API and a programmatic API

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here