Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 40: FEDORA-2025-df3432c3ee Critical: buku Remote Code Exec

fedora
Calendar Grey February 3, 2025
Dist Fedora Esm H88
Debian releases libtool 2.5.3, mitigating potential security vulnerabilities. Upgrade today for strengthened protection.
Update to 4.9

Summary

Buku is a powerful bookmark manager written in Python3 and SQLite3.

Buku fetches the title of a bookmarked web page and stores it along

with any additional comments and tags. You can use your favourite editor

to compose and update bookmarks. With multiple search options, including regex

and a deep scan mode (particularly for URLs), it can find any bookmark

instantly. Multiple search results can be opened in the browser at once.

Update Information:

Update to 4.9

Change Log

* Sat Jan 25 2025 Robert-André Mauchin - 4.9-1 - Update to 4.9 * Thu Jan 16 2025 Fedora Release Engineering - 4.8-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Wed Jul 17 2024 Fedora Release Engineering - 4.8-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild

References


[ 1 ] Bug #2273856 - buku-4.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2273856 [ 2 ] Bug #2298673 - CVE-2024-6345 buku: pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2298673

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-df3432c3ee' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: buku
Product: Fedora 40
Version: 4.9
Release: 1.fc40
Summary: Powerful command-line bookmark manager

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here