-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-af305bed3d 2023-03-30 00:18:30.537075 -------------------------------------------------------------------------------- Name : rizin Product : Fedora 38 Version : 0.5.1 Release : 1.fc38.2 URL : https://rizin.re/ Summary : UNIX-like reverse engineering framework and command-line tool-set Description : Rizin is a free and open-source Reverse Engineering framework, providing a complete binary analysis experience with features like Disassembler, Hexadecimal editor, Emulation, Binary inspection, Debugger, and more. Rizin is a fork of radare2 with a focus on usability, working features and code cleanliness. -------------------------------------------------------------------------------- Update Information: rebase rizin to v0.5.1 and cutter-re to 0.2.0 -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 14 2023 Riccardo Schirone- 0.5.1-1 - Rebase to upstream version 0.5.1 * Sun Feb 19 2023 Michal Ambroz - 0.5.0-1 - Rebase to upstream version 0.5.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2112239 - CVE-2022-34612 rizin: integer overflow in get_long_object() further leads to heap-overflow causing a crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2112239 [ 2 ] Bug #2124769 - CVE-2022-36042 rizin: rizin: Out-of-bounds Write in dyld cache binary plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2124769 [ 3 ] Bug #2125888 - cutter-re-2.2.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2125888 [ 4 ] Bug #2126126 - CVE-2022-36040 rizin: Out-of-bounds Write in pyc/marshal.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126126 [ 5 ] Bug #2126129 - CVE-2022-36041 rizin: Out-of-bounds Write in Mach-O binary plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126129 [ 6 ] Bug #2126130 - CVE-2022-36043 rizin: Double Free in bobj.c when using QNX binary plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126130 [ 7 ] Bug #2126131 - CVE-2022-36044 rizin: Out-of-bounds Write in Lua binary plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126131 [ 8 ] Bug #2171271 - rizin-0.5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2171271 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-af305bed3d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue