==========================================================================
Ubuntu Security Notice USN-6964-1
August 15, 2024

orc vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

ORC could be made to crash or execute arbitrary code

Software Description:
- orc: Library of Optimized Inner Loops Runtime Compiler

Details:

Noriko Totsuka discovered that ORC incorrectly handled certain
crafted file. An attacker could possibly use this issue to execute
arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
  liborc-0.4-0t64                 1:0.4.38-1ubuntu0.1

Ubuntu 22.04 LTS
  liborc-0.4-0                    1:0.4.32-2ubuntu0.1

Ubuntu 20.04 LTS
  liborc-0.4-0                    1:0.4.31-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-6964-1
  CVE-2024-40897

Package Information:
  https://launchpad.net/ubuntu/+source/orc/1:0.4.38-1ubuntu0.1
  https://launchpad.net/ubuntu/+source/orc/1:0.4.32-2ubuntu0.1
  https://launchpad.net/ubuntu/+source/orc/1:0.4.31-1ubuntu0.1

Ubuntu 6964-1: ORC Security Advisory Updates

August 15, 2024
ORC could be made to crash or execute arbitrary code

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: ORC could be made to crash or execute arbitrary code Software Description: - orc: Library of Optimized Inner Loops Runtime Compiler Details: Noriko Totsuka discovered that ORC incorrectly handled certain crafted file. An attacker could possibly use this issue to execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS liborc-0.4-0t64 1:0.4.38-1ubuntu0.1 Ubuntu 22.04 LTS liborc-0.4-0 1:0.4.32-2ubuntu0.1 Ubuntu 20.04 LTS liborc-0.4-0 1:0.4.31-1ubuntu0.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6964-1

CVE-2024-40897

Severity
Ubuntu Security Notice USN-6964-1

Package Information

https://launchpad.net/ubuntu/+source/orc/1:0.4.38-1ubuntu0.1 https://launchpad.net/ubuntu/+source/orc/1:0.4.32-2ubuntu0.1 https://launchpad.net/ubuntu/+source/orc/1:0.4.31-1ubuntu0.1

Related News