Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Patched libiniparser to fix CVE-2025-0633. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-257f422587 2025-03-14 02:12:06.905856+00:00 -------------------------------------------------------------------------------- Name : iniparser Product : Fedora 40 Version : 4.1 Release : 17.fc40 URL : https://github.com/ndevilla/iniparser Summary : C library for parsing "INI-style" files Description : iniParser is an ANSI C library to parse "INI-style" files, often used to hold application configuration information. -------------------------------------------------------------------------------- Update Information: Patched libiniparser to fix CVE-2025-0633 -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 26 2025 David Cantrell - 4.1-17 - Patch for CVE-2025-0633 - Heap Overflow in iniparser.c (#2346474) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2346474 - CVE-2025-0633 iniparser: Heap Overflow in iniparser.c https://bugzilla.redhat.com/show_bug.cgi?id=2346474 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-257f422587' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1237377 Cross-References: * CVE-2025-0633 . # Security update for iniparser Announcement ID: SUSE-SU-2025:0845-1 Release Date: 2025-03-12T09:33:00Z Rating: moderate References: * bsc#1237377 Cross-References: * CVE-2025-0633 CVSS scores: * CVE-2025-0633 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-0633 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-0633 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for iniparser fixes the following issues: * CVE-2025-0633: string copy into buffer without previous size validation leads to heap buffer overflow in iniparser_dumpsection_ini() of iniparser (bsc#1237377). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-845=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libiniparser0-debuginfo-32bit-3.1.0.git20140619_c5beb80a-3.6.1 * libiniparser0-3.1.0.git20140619_c5beb80a-3.6.1 * iniparser-debugsource-3.1.0.git20140619_c5beb80a-3.6.1 * libiniparser0-32bit-3.1.0.git20140619_c5beb80a-3.6.1 * libiniparser-devel-3.1.0.git20140619_c5beb80a-3.6.1 * libiniparser0-debuginfo-3.1.0.git20140619_c5beb80a-3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-0633.html *https://bugzilla.suse.com/show_bug.cgi?id=1237377 . SUSE update for iniparser addresses CVE-2025-0633 vulnerability, enhancing security for affected systems.. bsc#1237377, cross-references, cve-2025-0633, security, update, iniparser, announcement. . LinuxSecurity.com Team
* bsc#1237377 Cross-References: * CVE-2025-0633 . # Security update for iniparser Announcement ID: SUSE-SU-2025:0821-1 Release Date: 2025-03-10T15:03:27Z Rating: moderate References: * bsc#1237377 Cross-References: * CVE-2025-0633 CVSS scores: * CVE-2025-0633 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-0633 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-0633 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for iniparser fixes the following issues: * CVE-2025-0633: string copy into buffer without previous size validation leads to heap buffer overflow in iniparser_dumpsection_ini() of iniparser (bsc#1237377). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-821=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-821=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-821=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * libiniparser-devel-4.1-150500.4.8.1 * iniparser-debugsource-4.1-150500.4.8.1 * libiniparser1-debuginfo-4.1-150500.4.8.1 * libiniparser1-4.1-150500.4.8.1 * openSUSE Leap 15.5 (x86_64) * libiniparser1-32bit-4.1-150500.4.8.1 *libiniparser1-32bit-debuginfo-4.1-150500.4.8.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libiniparser1-64bit-4.1-150500.4.8.1 * libiniparser1-64bit-debuginfo-4.1-150500.4.8.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libiniparser-devel-4.1-150500.4.8.1 * iniparser-debugsource-4.1-150500.4.8.1 * libiniparser1-debuginfo-4.1-150500.4.8.1 * libiniparser1-4.1-150500.4.8.1 * openSUSE Leap 15.6 (x86_64) * libiniparser1-32bit-4.1-150500.4.8.1 * libiniparser1-32bit-debuginfo-4.1-150500.4.8.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libiniparser1-debuginfo-4.1-150500.4.8.1 * iniparser-debugsource-4.1-150500.4.8.1 * libiniparser1-4.1-150500.4.8.1 ## References: * https://www.suse.com/security/cve/CVE-2025-0633.html * https://bugzilla.suse.com/show_bug.cgi?id=1237377 . SUSE-SU-2025:0821-2 update for jsonparser resolves significant memory corruption vulnerabilities in impacted solutions.. security updates, buffer overflow patches, iniparser security, SUSE vulnerabilities. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for iniparser Announcement ID: SUSE-SU-2025:0821-1 Release Date: 2025-03-10T15:03:27Z Rating: moderate References: * bsc#1237377 Cross-References: * CVE-2025-0633 CVSS scores: * CVE-2025-0633 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-0633 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-0633 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for iniparser fixes the following issues: * CVE-2025-0633: string copy into buffer without previous size validation leads to heap buffer overflow in iniparser_dumpsection_ini() of iniparser (bsc#1237377). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-821=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-821=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-821=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * libiniparser-devel-4.1-150500.4.8.1 * iniparser-debugsource-4.1-150500.4.8.1 * libiniparser1-debuginfo-4.1-150500.4.8.1 * libiniparser1-4.1-150500.4.8.1 * openSUSE Leap 15.5 (x86_64) * libiniparser1-32bit-4.1-150500.4.8.1 * libiniparser1-32bit-debuginfo-4.1-150500.4.8.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libiniparser1-64bit-4.1-150500.4.8.1 * libiniparser1-64bit-debuginfo-4.1-150500.4.8.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libiniparser-devel-4.1-150500.4.8.1 * iniparser-debugsource-4.1-150500.4.8.1 * libiniparser1-debuginfo-4.1-150500.4.8.1 * libiniparser1-4.1-150500.4.8.1 * openSUSE Leap 15.6 (x86_64) * libiniparser1-32bit-4.1-150500.4.8.1 * libiniparser1-32bit-debuginfo-4.1-150500.4.8.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libiniparser1-debuginfo-4.1-150500.4.8.1 * iniparser-debugsource-4.1-150500.4.8.1 * libiniparser1-4.1-150500.4.8.1 ## References: * https://www.suse.com/security/cve/CVE-2025-0633.html * https://bugzilla.suse.com/show_bug.cgi?id=1237377 . The latest patch for iniparser resolves a significant vulnerability in several versions of openSUSE, mitigating potential buffer overflow risks.. openSUSE Update,iniparser Security Fix,buffer overflow Patch,security Advisory. . LinuxSecurity.com Team
A heap-based buffer overflow vulnerability in iniparser_dumpsection_ini() in iniparser allows an attacker to read out-of-bounds memory. (CVE-2025-0633) References: . MGASA-2025-0077 - Updated iniparser packages fix security vulnerability Publication date: 26 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0077.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-0633 A heap-based buffer overflow vulnerability in iniparser_dumpsection_ini() in iniparser allows an attacker to read out-of-bounds memory. (CVE-2025-0633) References: - https://bugs.mageia.org/show_bug.cgi?id=34047 - https://ubuntu.com/security/notices/USN-7286-1 - https://www.cve.org/CVERecord?id=CVE-2025-0633 SRPMS: - 9/core/iniparser-4.1-4.1.mga9 . Heap overflow vulnerability in iniparser permits unauthorized memory access. Remedial measures provided in subsequent patches.. Heap-Based Overflow, Iniparser Security, Mageia Update, Buffer Overflow Risk. . Severity: Critical. LinuxSecurity.com Team
iniparser could be made to crash if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7286-1 February 24, 2025 iniparser vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: iniparser could be made to crash if it opened a specially crafted file. Software Description: - iniparser: INI file reader/writer Details: It was discovered that iniParser incorrectly handled certain files. An attacker could possibly use this issue to cause iniParser to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 libiniparser1 4.2.1-1ubuntu0.1 Ubuntu 24.04 LTS libiniparser1 4.1-7ubuntu0.1 Ubuntu 22.04 LTS libiniparser1 4.1-4ubuntu4.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7286-1 CVE-2025-0633 Package Information: https://launchpad.net/ubuntu/+source/iniparser/4.2.1-1ubuntu0.1 https://launchpad.net/ubuntu/+source/iniparser/4.1-7ubuntu0.1 https://launchpad.net/ubuntu/+source/iniparser/4.1-4ubuntu4.2 . Ubuntu Security Notice USN-7286-1 addresses a vulnerability in iniparser, reported on February 24, 2025, outlining steps for users to safeguard their systems.. iniparser updates, Ubuntu security, denial of service, software vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for iniparser ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0183-1 Rating: moderate References: #1211889 Cross-References: CVE-2023-33461 CVSS scores: CVE-2023-33461 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2023-33461 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for iniparser fixes the following issues: - CVE-2023-33461: Fixed a NULL pointer dereference in iniparser_getboolean() (boo#1211889) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-183=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): libiniparser-devel-4.1-bp154.2.3.1 libiniparser1-4.1-bp154.2.3.1 - openSUSE Backports SLE-15-SP4 (aarch64_ilp32): libiniparser1-64bit-4.1-bp154.2.3.1 - openSUSE Backports SLE-15-SP4 (x86_64): libiniparser1-32bit-4.1-bp154.2.3.1 References: https://www.suse.com/security/cve/CVE-2023-33461.html https://bugzilla.suse.com/1211889 . openSUSE reveals Security Patch for iniparser related to CVE-2023-33461 with moderate impact. Update accessible immediately.. openSUSE Security Update,iniparser patch,threat mitigation. . LinuxSecurity.com Team
Security fix for CVE-2023-33461. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-6454c8edea 2023-06-18 01:13:43.952661 --------------------------------------------------------------------------------Name : iniparser Product : Fedora 37 Version : 4.1 Release : 11.fc37 URL : https://github.com/ndevilla/iniparser Summary : C library for parsing "INI-style" files Description : iniParser is an ANSI C library to parse "INI-style" files, often used to hold application configuration information. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2023-33461 --------------------------------------------------------------------------------ChangeLog: * Wed Jun 14 2023 David Cantrell - 4.1-11 - Fix for CVE-2023-33461 (BZ#2211621) --------------------------------------------------------------------------------References: [ 1 ] Bug #2211618 - CVE-2023-33461 iniparser: NULL pointer cause crash in iniparser_getboolean https://bugzilla.redhat.com/show_bug.cgi?id=2211618 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6454c8edea' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.