Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 40: FEDORA-2025-93d6242840 moderate: yq security update

fedora
Calendar Grey February 5, 2025
Dist Fedora Esm H88
A security vulnerability in the `yq` tool (CVE-2024-45338) could jeopardize data processing integrity. Update to version 4.33.1 or newer to safeguard your systems
Rebuilt against golang-x-net 0.33.0 for CVE-2024-45338

Summary

Yq is a portable command-line YAML, JSON, XML, CSV, TOML and properties

processor.

Update Information:

Rebuilt against golang-x-net 0.33.0 for CVE-2024-45338

Change Log

* Sun Jan 26 2025 Michel Lind - 4.43.1-5 - Fix building with Go 1.24; Resolves: RHBZ#2341595 * Sun Jan 19 2025 Fedora Release Engineering - 4.43.1-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Sat Jul 20 2024 Fedora Release Engineering - 4.43.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild

References


[ 1 ] Bug #2333241 - CVE-2024-45338 yq: Non-linear parsing of case-insensitive content in golang.org/x/net/html [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2333241

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-93d6242840' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: yq
Product: Fedora 40
Version: 4.43.1
Release: 5.fc40
Summary: Yq is a portable command-line YAML, JSON, XML, CSV, TOML and properties processor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here