* bsc#1219210 Cross-References: * CVE-2024-0911 . # Security update for indent Announcement ID: SUSE-SU-2024:1134-1 Rating: moderate References: * bsc#1219210 Cross-References: * CVE-2024-0911 CVSS scores: * CVE-2024-0911 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2024-0911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for indent fixes the following issues: * CVE-2024-0911: Fixed heap-based buffer overflow in set_buf_break() (bsc#1219210). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-1134=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * indent-debugsource-2.2.10-38.9.1 * indent-2.2.10-38.9.1 * indent-debuginfo-2.2.10-38.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-0911.html * https://bugzilla.suse.com/show_bug.cgi?id=1219210 . A safety patch for indent, identified as SUSE-SU-2024:1134-1, tackles a noteworthy buffer overflow vulnerability.. SUSE Security Update, Indent Software Patch, Moderate Risk Management. . LinuxSecurity.com Team
* bsc#1219210 Cross-References: * CVE-2024-0911 . # Security update for indent Announcement ID: SUSE-SU-2024:0965-1 Rating: moderate References: * bsc#1219210 Cross-References: * CVE-2024-0911 CVSS scores: * CVE-2024-0911 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2024-0911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * Development Tools Module 15-SP5 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for indent fixes the following issues: * CVE-2024-0911: Fixed heap-based buffer overflow in set_buf_break() (bsc#1219210). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2024-965=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-965=1 ## Package List: * Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64) * indent-debuginfo-2.2.11-150000.3.9.1 * indent-2.2.11-150000.3.9.1 * indent-debugsource-2.2.11-150000.3.9.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * indent-debuginfo-2.2.11-150000.3.9.1 * indent-2.2.11-150000.3.9.1 * indent-debugsource-2.2.11-150000.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-0911.html * https://bugzilla.suse.com/show_bug.cgi?id=1219210 . Patch released for addressing a medium severity buffer overflow in indent affecting multiple SUSE platforms. Ensure timely installation of updates.. SUSE Security Update, Indent Patch,Development Tools Fix, Heap Overflow. . LinuxSecurity.com Team
GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file. (CVE-2023-40305) GNU indent 2.2.13 has a heap overread in lexi(). . MGASA-2023-0274 - Updated indent package fixes security vulnerabilities Publication date: 30 Sep 2023 URL: https://advisories.mageia.org/MGASA-2023-0274.html Type: security Affected Mageia releases: 8, 9 CVE: CVE-2023--40305 GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file. (CVE-2023-40305) GNU indent 2.2.13 has a heap overread in lexi(). References: - https://bugs.mageia.org/show_bug.cgi?id=32273 - https://www.cve.org/CVERecord?id=CVE-2023-40305 - https://lists.fedoraproject.org/archives/list/
Indent could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-6389-1 September 20, 2023 indent vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Indent could be made to crash or run programs if it opened a specially crafted file. Software Description: - indent: C language source code formatting program Details: It was discovered that Indent incorrectly handled parsing certain source files. If a user or automated system were tricked into processing a specially crafted source file, a remote attacker could use this issue to cause Indent to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: indent 2.2.12-4ubuntu0.1 Ubuntu 22.04 LTS: indent 2.2.12-1ubuntu0.22.04.1 Ubuntu 20.04 LTS: indent 2.2.12-1ubuntu0.20.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6389-1 CVE-2023-40305 Package Information: https://launchpad.net/ubuntu/+source/indent/2.2.12-4ubuntu0.1 https://launchpad.net/ubuntu/+source/indent/2.2.12-1ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/indent/2.2.12-1ubuntu0.20.04.1 . A critical vulnerability in Debian may result in system instability or allow malicious code execution through specially designed files.. Indent Vulnerability, Ubuntu Security, Denial Of Service. . Severity: Critical. LinuxSecurity.com Team
This release fixes a heap buffer overwrite in search_brace() (CVE-2023-40305) and a heap overread in lexi().. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-845edc1181 2023-09-15 18:36:13.239410 -------------------------------------------------------------------------------- Name : indent Product : Fedora 39 Version : 2.2.13 Release : 5.fc39 URL : Summary : A GNU program for formatting C code Description : Indent is a GNU program for beautifying C code, so that it is easier to read. Indent can also convert from one C writing style to a different one. Indent understands correct C syntax and tries to handle incorrect C syntax. Install the indent package if you are developing applications in C and you want a program to format your code. -------------------------------------------------------------------------------- Update Information: This release fixes a heap buffer overwrite in search_brace() (CVE-2023-40305) and a heap overread in lexi(). -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 16 2023 Petr Pisar - 2.2.13-5 - Fix a heap overread in search_brace/lexi - Fix CVE-2023-40305 (a heap buffer overwrite in search_brace) (bug #2231919) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2231854 - CVE-2023-40305 indent: heap-based buffer overflow in search_brace() in indent.c https://bugzilla.redhat.com/show_bug.cgi?id=2231854 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-845edc1181' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPGkeys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
This release fixes a heap buffer overwrite in search_brace() (CVE-2023-40305) and a heap overread in lexi().. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-67d8bcb63c 2023-09-07 01:42:04.670724 -------------------------------------------------------------------------------- Name : indent Product : Fedora 37 Version : 2.2.13 Release : 4.fc37 URL : Summary : A GNU program for formatting C code Description : Indent is a GNU program for beautifying C code, so that it is easier to read. Indent can also convert from one C writing style to a different one. Indent understands correct C syntax and tries to handle incorrect C syntax. Install the indent package if you are developing applications in C and you want a program to format your code. -------------------------------------------------------------------------------- Update Information: This release fixes a heap buffer overwrite in search_brace() (CVE-2023-40305) and a heap overread in lexi(). -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 16 2023 Petr Pisar - 2.2.13-4 - Fix a heap overread in search_brace/lexi - Fix CVE-2023-40305 (a heap buffer overwrite in search_brace) (bug #2231919) * Mon Apr 17 2023 Petr Pisar - 2.2.13-3 - Correct a license to "GPL-3.0-or-later AND BSD-3-Clause AND BSD-4.3TAHOE AND Latex2e-translated-notice" -------------------------------------------------------------------------------- References: [ 1 ] Bug #2231854 - CVE-2023-40305 indent: heap-based buffer overflow in search_brace() in indent.c https://bugzilla.redhat.com/show_bug.cgi?id=2231854 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-67d8bcb63c' at the command line. For more information, refer to the dnf documentationavailable at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
This release fixes a heap buffer overwrite in search_brace() (CVE-2023-40305) and a heap overread in lexi().. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-b7f5059ee9 2023-09-07 01:27:49.829977 -------------------------------------------------------------------------------- Name : indent Product : Fedora 38 Version : 2.2.13 Release : 4.fc38 URL : Summary : A GNU program for formatting C code Description : Indent is a GNU program for beautifying C code, so that it is easier to read. Indent can also convert from one C writing style to a different one. Indent understands correct C syntax and tries to handle incorrect C syntax. Install the indent package if you are developing applications in C and you want a program to format your code. -------------------------------------------------------------------------------- Update Information: This release fixes a heap buffer overwrite in search_brace() (CVE-2023-40305) and a heap overread in lexi(). -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 16 2023 Petr Pisar - 2.2.13-4 - Fix a heap overread in search_brace/lexi - Fix CVE-2023-40305 (a heap buffer overwrite in search_brace) (bug #2231919) * Mon Apr 17 2023 Petr Pisar - 2.2.13-3 - Correct a license to "GPL-3.0-or-later AND BSD-3-Clause AND BSD-4.3TAHOE AND Latex2e-translated-notice" -------------------------------------------------------------------------------- References: [ 1 ] Bug #2231854 - CVE-2023-40305 indent: heap-based buffer overflow in search_brace() in indent.c https://bugzilla.redhat.com/show_bug.cgi?id=2231854 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-b7f5059ee9' at the command line. For more information, refer to the dnf documentationavailable at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Multiple memory safety issues (bsc#1209718). References: - https://bugs.mageia.org/show_bug.cgi?id=31884 - https://lists.suse.com/pipermail/sle-security-updates/2023-April/014560.html . MGASA-2023-0168 - Updated indent packages fix security vulnerability Publication date: 16 May 2023 URL: https://advisories.mageia.org/MGASA-2023-0168.html Type: security Affected Mageia releases: 8 Multiple memory safety issues (bsc#1209718). References: - https://bugs.mageia.org/show_bug.cgi?id=31884 - https://lists.suse.com/pipermail/sle-security-updates/2023-April/014560.html SRPMS: - 8/core/indent-2.2.13-1.mga8 . Numerous vulnerabilities concerning memory safety resolved in Mageia's indent update, launched on May 16, 2023. Explore further details within.. mageia update,memory safety fixes,indent security update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.