Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 39: Advisory FEDORA-2024-270cd506bb Critical: Clojure DoS Issue

fedora
Calendar Grey March 24, 2024
Dist Fedora Esm H88
Important security patch for Clojure on Fedora 39 tackling Denial of Service issues. Upgrade to version 1.11.2 is now ready.
Security fix for CVE-2024-22871 Update to upstream release 1.11.2

Summary

Clojure is a dynamic programming language that targets the Java

Virtual Machine. It is designed to be a general-purpose language,

combining the approachability and interactive development of a

scripting language with an efficient and robust infrastructure for

multithreaded programming. Clojure is a compiled language - it

compiles directly to JVM bytecode, yet remains completely

dynamic. Every feature supported by Clojure is supported at

runtime. Clojure provides easy access to the Java frameworks, with

optional type hints and type inference, to ensure that calls to Java

can avoid reflection.

Update Information:

Security fix for CVE-2024-22871 Update to upstream release 1.11.2

Change Log

* Fri Mar 15 2024 Markku Korkeala - 1:1.11.2-1 - Update to upstream release 1.11.2 * Wed Jan 24 2024 Fedora Release Engineering - 1:1.11.1-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Fedora Release Engineering - 1:1.11.1-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

References


[ 1 ] Bug #2266785 - CVE-2024-22871 clojure: denial of service (DoS) via the clojure.core$partial$fn__5920 function. https://bugzilla.redhat.com/show_bug.cgi?id=2266785

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-270cd506bb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: clojure
Product: Fedora 39
Version: 1.11.2
Release: 1.fc39
Summary: A dynamic programming language that targets the Java Virtual Machine

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here