Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 39 FEDORA-2024-50ff19c3e8: Critical libipuz Remote Code Execution

fedora
Calendar Grey June 2, 2024
Dist Fedora Esm H88
The recent libipuz update in Fedora 39 addresses bugs and boosts security—essential for any Rust development.
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries)

Summary

This is a library for parsing .ipuz puzzle files, for crossword puzzles,

sudokus, etc. The library only handles crosswords for now.

Update Information:

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html

Change Log

* Fri May 24 2024 Fabio Valentini - 0.4.6.2-2 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces

References

Fedora Update Notification FEDORA-2024-40ee18b2e7 2024-06-02 03:36:56.060441 Name : libipuz Product : Fedora 39 Version : 0.4.6.2 Release : 2.fc39 URL : Summary : Library for parsing .ipuz puzzle files Description : This is a library for parsing .ipuz puzzle files, for crossword puzzles, sudokus, etc. The library only handles crosswords for now.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-40ee18b2e7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libipuz
Product: Fedora 39
Version: 0.4.6.2
Release: 2.fc39
URL:
Summary: Library for parsing .ipuz puzzle files

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here