Update to tree-sitter 0.25.2 and emacs 30.1.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-5b272a55b8 2025-03-10 16:13:35.332619+00:00 -------------------------------------------------------------------------------- Name : rizin Product : Fedora 42 Version : 0.7.4 Release : 8.fc42 URL : https://rizin.re/ Summary : UNIX-like reverse engineering framework and command-line tool-set Description : Rizin is a free and open-source Reverse Engineering framework, providing a complete binary analysis experience with features like Disassembler, Hexadecimal editor, Emulation, Binary inspection, Debugger, and more. Rizin is a fork of radare2 with a focus on usability, working features and code cleanliness. -------------------------------------------------------------------------------- Update Information: Update to tree-sitter 0.25.2 and emacs 30.1. -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 19 2025 Peter Oliver - 0.7.4-5 - Rebuild against tree-sitter-0.25.2-3.fc43 * Mon Feb 3 2025 Peter Oliver - 0.7.4-4 - Rebuild against tree-sitter-0.25.1-6.fc42 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2343305 - tree-sitter-0.25.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2343305 [ 2 ] Bug #2347206 - emacs-30.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2347206 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-5b272a55b8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used bythe Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-6f77f6c77a 2025-03-01 01:38:57.010399+00:00 -------------------------------------------------------------------------------- Name : cutter-re Product : Fedora 40 Version : 2.3.4 Release : 6.fc40 URL : https://cutter.re/ Summary : GUI for Rizin reverse engineering framework Description : Cutter is a Qt and C++ GUI for Rizin. Its goal is making an advanced, customizable and FOSS reverse-engineering platform while keeping the user experience at mind. Cutter is created by reverse engineers for reverse engineers. -------------------------------------------------------------------------------- Update Information: CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code rizin 0.7.2 / cutter-re 2.3.4 (fix changelog) rizin 0.7.2 / cutter-re 2.3.4 -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 16 2025 Fedora Release Engineering - 2.3.4-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Wed Jan 1 2025 Michal Ambroz - 2.3.4-5 - Rebuild with new version of rizin 0.7.4 * Wed Jul 17 2024 Fedora Release Engineering - 2.3.4-4 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2333933 - CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2333933 [ 2 ] Bug #2333934 - CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2333934 [ 3 ] Bug #2340020 - cutter-re: FTBFS in Fedora rawhide/f42 https://bugzilla.redhat.com/show_bug.cgi?id=2340020 [ 4 ] Bug #2346253 - Non-responsive maintainer check for ret2libc https://bugzilla.redhat.com/show_bug.cgi?id=2346253 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6f77f6c77a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-6f77f6c77a 2025-03-01 01:38:57.010399+00:00 -------------------------------------------------------------------------------- Name : rizin Product : Fedora 40 Version : 0.7.4 Release : 5.fc40 URL : https://rizin.re/ Summary : UNIX-like reverse engineering framework and command-line tool-set Description : Rizin is a free and open-source Reverse Engineering framework, providing a complete binary analysis experience with features like Disassembler, Hexadecimal editor, Emulation, Binary inspection, Debugger, and more. Rizin is a fork of radare2 with a focus on usability, working features and code cleanliness. -------------------------------------------------------------------------------- Update Information: CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code rizin 0.7.2 / cutter-re 2.3.4 (fix changelog) rizin 0.7.2 / cutter-re 2.3.4 -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 19 2025 Peter Oliver - 0.7.4-5 - Rebuild against tree-sitter-0.25.2-3.fc43 * Mon Feb 3 2025 Peter Oliver - 0.7.4-4 - Rebuild against tree-sitter-0.25.1-6.fc42 * Sat Jan 18 2025 Fedora Release Engineering - 0.7.4-3 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Tue Dec 31 2024 Michal Ambroz - 0.7.4-2 - bump to version 0.7.4 * Sun Sep 1 2024 Yaakov Selkowitz - 0.7.3-3 - Rebuilt for tree-sitter 0.23.0 * Fri Jul 19 2024 Fedora Release Engineering - 0.7.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2333933 - CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2333933 [ 2 ] Bug #2333934 - CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2333934 [ 3 ] Bug #2340020 - cutter-re: FTBFS in Fedora rawhide/f42 https://bugzilla.redhat.com/show_bug.cgi?id=2340020 [ 4 ] Bug #2346253 - Non-responsive maintainer check for ret2libc https://bugzilla.redhat.com/show_bug.cgi?id=2346253 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6f77f6c77a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-1290a47fff 2025-03-01 01:22:54.667719+00:00 -------------------------------------------------------------------------------- Name : rizin Product : Fedora 41 Version : 0.7.4 Release : 5.fc41 URL : https://rizin.re/ Summary : UNIX-like reverse engineering framework and command-line tool-set Description : Rizin is a free and open-source Reverse Engineering framework, providing a complete binary analysis experience with features like Disassembler, Hexadecimal editor, Emulation, Binary inspection, Debugger, and more. Rizin is a fork of radare2 with a focus on usability, working features and code cleanliness. -------------------------------------------------------------------------------- Update Information: CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 19 2025 Peter Oliver - 0.7.4-5 - Rebuild against tree-sitter-0.25.2-3.fc43 * Mon Feb 3 2025 Peter Oliver - 0.7.4-4 - Rebuild against tree-sitter-0.25.1-6.fc42 * Sat Jan 18 2025 Fedora Release Engineering - 0.7.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Tue Dec 31 2024 Michal Ambroz - 0.7.4-2 - bump to version0.7.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2333933 - CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2333933 [ 2 ] Bug #2333934 - CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2333934 [ 3 ] Bug #2340020 - cutter-re: FTBFS in Fedora rawhide/f42 https://bugzilla.redhat.com/show_bug.cgi?id=2340020 [ 4 ] Bug #2346253 - Non-responsive maintainer check for ret2libc https://bugzilla.redhat.com/show_bug.cgi?id=2346253 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1290a47fff' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Command injection via RzBinInfo bclass due legacy code. (CVE-2022-1207) References: - https://bugs.mageia.org/show_bug.cgi?id=33895 - . MGASA-2025-0005 - Updated rizin packages fix security vulnerability Publication date: 12 Jan 2025 URL: https://advisories.mageia.org/MGASA-2025-0005.html Type: security Affected Mageia releases: 9 CVE: CVE-2022-1207 Command injection via RzBinInfo bclass due legacy code. (CVE-2022-1207) References: - https://bugs.mageia.org/show_bug.cgi?id=33895 - - https://github.com/rizinorg/rizin/security/advisories/GHSA-5jhc-frm4-p8v9 - https://www.cve.org/CVERecord?id=CVE-2022-1207 SRPMS: - 9/core/rizin-0.5.2-1.1.mga9 . Revised rizin distributions address security flaws affecting older code through RzBinInfo. Comprehensive information included.. command injection,rizin update,mageia security,legacy code,coding vulnerabilities. . LinuxSecurity.com Team
rebase to rizin 0.5.2 and cutter 2.2.1. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-3dc1f9ba12 2023-07-12 01:25:39.603769 --------------------------------------------------------------------------------Name : rizin Product : Fedora 38 Version : 0.5.2 Release : 1.fc38.2 URL : https://rizin.re/ Summary : UNIX-like reverse engineering framework and command-line tool-set Description : Rizin is a free and open-source Reverse Engineering framework, providing a complete binary analysis experience with features like Disassembler, Hexadecimal editor, Emulation, Binary inspection, Debugger, and more. Rizin is a fork of radare2 with a focus on usability, working features and code cleanliness. --------------------------------------------------------------------------------Update Information: rebase to rizin 0.5.2 and cutter 2.2.1 --------------------------------------------------------------------------------ChangeLog: * Wed May 17 2023 Riccardo Schirone - 0.5.2-1 - Rebase to upstream version 0.5.2 --------------------------------------------------------------------------------References: [ 1 ] Bug #2178823 - CVE-2023-27590 rizin: stack-based buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2178823 [ 2 ] Bug #2182162 - rizin-0.5.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2182162 [ 3 ] Bug #2203912 - cutter-re-2.2.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2203912 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-3dc1f9ba12' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used bythe Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
rebase rizin to v0.5.1 and cutter-re to 0.2.0. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-af305bed3d 2023-03-30 00:18:30.537075 --------------------------------------------------------------------------------Name : cutter-re Product : Fedora 38 Version : 2.2.0 Release : 1.fc38 URL : https://cutter.re/ Summary : GUI for Rizin reverse engineering framework Description : Cutter is a Qt and C++ GUI for Rizin. Its goal is making an advanced, customizable and FOSS reverse-engineering platform while keeping the user experience at mind. Cutter is created by reverse engineers for reverse engineers. --------------------------------------------------------------------------------Update Information: rebase rizin to v0.5.1 and cutter-re to 0.2.0 --------------------------------------------------------------------------------ChangeLog: * Tue Mar 14 2023 Riccardo Schirone - 2.2.0-1 - Rebase to version 2.2.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #2112239 - CVE-2022-34612 rizin: integer overflow in get_long_object() further leads to heap-overflow causing a crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2112239 [ 2 ] Bug #2124769 - CVE-2022-36042 rizin: rizin: Out-of-bounds Write in dyld cache binary plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2124769 [ 3 ] Bug #2125888 - cutter-re-2.2.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2125888 [ 4 ] Bug #2126126 - CVE-2022-36040 rizin: Out-of-bounds Write in pyc/marshal.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126126 [ 5 ] Bug #2126129 - CVE-2022-36041 rizin: Out-of-bounds Write in Mach-O binary plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126129 [ 6 ] Bug #2126130 - CVE-2022-36043 rizin: Double Free in bobj.c when using QNX binaryplugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126130 [ 7 ] Bug #2126131 - CVE-2022-36044 rizin: Out-of-bounds Write in Lua binary plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126131 [ 8 ] Bug #2171271 - rizin-0.5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2171271 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-af305bed3d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- Rebase to upstream version 0.4.1 to fix some security issues. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-0c34c7d5e1 2022-09-20 00:15:19.075545 --------------------------------------------------------------------------------Name : rizin Product : Fedora 37 Version : 0.4.1 Release : 1.fc37 URL : https://rizin.re/ Summary : UNIX-like reverse engineering framework and command-line tool-set Description : Rizin is a free and open-source Reverse Engineering framework, providing a complete binary analysis experience with features like Disassembler, Hexadecimal editor, Emulation, Binary inspection, Debugger, and more. Rizin is a fork of radare2 with a focus on usability, working features and code cleanliness. --------------------------------------------------------------------------------Update Information: - Rebase to upstream version 0.4.1 to fix some security issues --------------------------------------------------------------------------------ChangeLog: * Sat Sep 10 2022 Richard Hughes - 0.4.1-1 - Rebase to upstream version 0.4.1 - Fixed CVE-2022-36039 - Fixed CVE-2022-36040 - Fixed CVE-2022-36041 - Fixed CVE-2022-36042 - Fixed CVE-2022-36043 - Fixed CVE-2022-36044 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-0c34c7d5e1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.