MGASA-2024-0241 - Updated erofs-utils packages fix security vulnerabilities

Publication date: 28 Jun 2024
URL: https://advisories.mageia.org/MGASA-2024-0241.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2023-33551,
     CVE-2023-33552

Heap Buffer Overflow in the erofsfsck_dirent_iter function in
fsck/main.c in erofs-utils v1.6 allows remote attackers to execute
arbitrary code via a crafted erofs filesystem image.

References:
- https://bugs.mageia.org/show_bug.cgi?id=32272
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FHOIRL6XH5NYR3LYI3KP5DE4SDSQWR7W/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33551
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33552

SRPMS:
- 9/core/erofs-utils-1.7.1-1.mga9

Mageia 2024-0241: erofs-utils Security Advisory Updates

Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image

Summary

Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image.

References

- https://bugs.mageia.org/show_bug.cgi?id=32272

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FHOIRL6XH5NYR3LYI3KP5DE4SDSQWR7W/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33551

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33552

Resolution

MGASA-2024-0241 - Updated erofs-utils packages fix security vulnerabilities

SRPMS

- 9/core/erofs-utils-1.7.1-1.mga9

Severity
Publication date: 28 Jun 2024
URL: https://advisories.mageia.org/MGASA-2024-0241.html
Type: security
CVE: CVE-2023-33551, CVE-2023-33552

Related News