--------------------------------------------------------------------------------Fedora Update Notification
FEDORA-2023-af305bed3d
2023-03-30 00:18:30.537075
--------------------------------------------------------------------------------Name        : rizin
Product     : Fedora 38
Version     : 0.5.1
Release     : 1.fc38.2
URL         : https://rizin.re/
Summary     : UNIX-like reverse engineering framework and command-line tool-set
Description :
Rizin is a free and open-source Reverse Engineering framework, providing a
complete binary analysis experience with features like Disassembler,
Hexadecimal editor, Emulation, Binary inspection, Debugger, and more.

Rizin is a fork of radare2 with a focus on usability, working features and code
cleanliness.

--------------------------------------------------------------------------------Update Information:

rebase rizin to v0.5.1 and cutter-re to 0.2.0
--------------------------------------------------------------------------------ChangeLog:

* Tue Mar 14 2023 Riccardo Schirone  - 0.5.1-1
- Rebase to upstream version 0.5.1
* Sun Feb 19 2023 Michal Ambroz  - 0.5.0-1
- Rebase to upstream version 0.5.0
--------------------------------------------------------------------------------References:

  [ 1 ] Bug #2112239 - CVE-2022-34612 rizin: integer overflow in get_long_object() further leads to heap-overflow causing a crash [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2112239
  [ 2 ] Bug #2124769 - CVE-2022-36042 rizin:  rizin: Out-of-bounds Write in dyld cache binary plugin [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2124769
  [ 3 ] Bug #2125888 - cutter-re-2.2.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2125888
  [ 4 ] Bug #2126126 - CVE-2022-36040 rizin: Out-of-bounds Write in pyc/marshal.c [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2126126
  [ 5 ] Bug #2126129 - CVE-2022-36041 rizin: Out-of-bounds Write in Mach-O binary plugin [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2126129
  [ 6 ] Bug #2126130 - CVE-2022-36043 rizin: Double Free in bobj.c when using QNX binary plugin [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2126130
  [ 7 ] Bug #2126131 - CVE-2022-36044 rizin: Out-of-bounds Write in Lua binary plugin [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2126131
  [ 8 ] Bug #2171271 - rizin-0.5.1 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2171271
--------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2023-af305bed3d' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/
Do not reply to spam, report it: https://pagure.io/login/

Fedora 38: rizin 2023-af305bed3d

March 30, 2023
rebase rizin to v0.5.1 and cutter-re to 0.2.0

Summary

Rizin is a free and open-source Reverse Engineering framework, providing a

complete binary analysis experience with features like Disassembler,

Hexadecimal editor, Emulation, Binary inspection, Debugger, and more.

Rizin is a fork of radare2 with a focus on usability, working features and code

cleanliness.

rebase rizin to v0.5.1 and cutter-re to 0.2.0

* Tue Mar 14 2023 Riccardo Schirone - 0.5.1-1

- Rebase to upstream version 0.5.1

* Sun Feb 19 2023 Michal Ambroz - 0.5.0-1

- Rebase to upstream version 0.5.0

[ 1 ] Bug #2112239 - CVE-2022-34612 rizin: integer overflow in get_long_object() further leads to heap-overflow causing a crash [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2112239

[ 2 ] Bug #2124769 - CVE-2022-36042 rizin: rizin: Out-of-bounds Write in dyld cache binary plugin [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2124769

[ 3 ] Bug #2125888 - cutter-re-2.2.0 is available

https://bugzilla.redhat.com/show_bug.cgi?id=2125888

[ 4 ] Bug #2126126 - CVE-2022-36040 rizin: Out-of-bounds Write in pyc/marshal.c [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2126126

[ 5 ] Bug #2126129 - CVE-2022-36041 rizin: Out-of-bounds Write in Mach-O binary plugin [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2126129

[ 6 ] Bug #2126130 - CVE-2022-36043 rizin: Double Free in bobj.c when using QNX binary plugin [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2126130

[ 7 ] Bug #2126131 - CVE-2022-36044 rizin: Out-of-bounds Write in Lua binary plugin [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2126131

[ 8 ] Bug #2171271 - rizin-0.5.1 is available

https://bugzilla.redhat.com/show_bug.cgi?id=2171271

su -c 'dnf upgrade --advisory FEDORA-2023-af305bed3d' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it: https://pagure.io/login/

FEDORA-2023-af305bed3d 2023-03-30 00:18:30.537075 Product : Fedora 38 Version : 0.5.1 Release : 1.fc38.2 URL : https://rizin.re/ Summary : UNIX-like reverse engineering framework and command-line tool-set Description : Rizin is a free and open-source Reverse Engineering framework, providing a complete binary analysis experience with features like Disassembler, Hexadecimal editor, Emulation, Binary inspection, Debugger, and more. Rizin is a fork of radare2 with a focus on usability, working features and code cleanliness. rebase rizin to v0.5.1 and cutter-re to 0.2.0 * Tue Mar 14 2023 Riccardo Schirone - 0.5.1-1 - Rebase to upstream version 0.5.1 * Sun Feb 19 2023 Michal Ambroz - 0.5.0-1 - Rebase to upstream version 0.5.0 [ 1 ] Bug #2112239 - CVE-2022-34612 rizin: integer overflow in get_long_object() further leads to heap-overflow causing a crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2112239 [ 2 ] Bug #2124769 - CVE-2022-36042 rizin: rizin: Out-of-bounds Write in dyld cache binary plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2124769 [ 3 ] Bug #2125888 - cutter-re-2.2.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2125888 [ 4 ] Bug #2126126 - CVE-2022-36040 rizin: Out-of-bounds Write in pyc/marshal.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126126 [ 5 ] Bug #2126129 - CVE-2022-36041 rizin: Out-of-bounds Write in Mach-O binary plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126129 [ 6 ] Bug #2126130 - CVE-2022-36043 rizin: Double Free in bobj.c when using QNX binary plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126130 [ 7 ] Bug #2126131 - CVE-2022-36044 rizin: Out-of-bounds Write in Lua binary plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126131 [ 8 ] Bug #2171271 - rizin-0.5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2171271 su -c 'dnf upgrade --advisory FEDORA-2023-af305bed3d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/ Do not reply to spam, report it: https://pagure.io/login/

Change Log

References

Update Instructions

Severity
Product : Fedora 38
Version : 0.5.1
Release : 1.fc38.2
URL : https://rizin.re/
Summary : UNIX-like reverse engineering framework and command-line tool-set

Related News