Patched libiniparser to fix CVE-2025-0633. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a1d884e467 2025-03-01 01:22:54.667783+00:00 -------------------------------------------------------------------------------- Name : iniparser Product : Fedora 41 Version : 4.2.4 Release : 3.fc41 URL : https://github.com/ndevilla/iniparser Summary : C library for parsing "INI-style" files Description : iniParser is an ANSI C library to parse "INI-style" files, often used to hold application configuration information. -------------------------------------------------------------------------------- Update Information: Patched libiniparser to fix CVE-2025-0633 -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 25 2025 David Cantrell - 4.2.4-3 - Patch for CVE-2025-0633 - Heap Overflow in iniparser.c (#2346474) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2346474 - CVE-2025-0633 iniparser: Heap Overflow in iniparser.c https://bugzilla.redhat.com/show_bug.cgi?id=2346474 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a1d884e467' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # libiniparser-devel-4.2.6-1.1 on GA media Announcement ID: openSUSE-SU-2025:14836-1 Rating: moderate Cross-References: * CVE-2025-0633 CVSS scores: * CVE-2025-0633 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-0633 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the libiniparser-devel-4.2.6-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * libiniparser-devel 4.2.6-1.1 * libiniparser4 4.2.6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-0633.html . The latest update from openSUSE Tumbleweed includes a crucial security notice regarding libiniparser-devel, concerning CVE-2025-0633.. openSUSE Tumbleweed, libiniparser-devel, security updates. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.