--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2023-b4b77f950c
2023-09-13 01:34:55.169250
--------------------------------------------------------------------------------

Name        : libeconf
Product     : Fedora 37
Version     : 0.5.2
Release     : 1.fc37
URL         : https://github.com/openSUSE/libeconf
Summary     : Enhanced config file parser library
Description :
libeconf is a highly flexible and configurable library to parse and manage
key=value configuration files. It reads configuration file snippets from
different directories and builds the final configuration file from it.

--------------------------------------------------------------------------------
Update Information:

Rebase to 0.5.2 to fix CVE-2023-22652 and CVE-2023-30079
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 28 2023 Iker Pedrosa  - 0.5.2-1
- Update to 0.5.2 (RH#1980774)
- Fix CVE-2023-22652 (RH#2212464)
- Fix CVE-2023-30079 (RH#2235236)
* Thu Jul 20 2023 Fedora Release Engineering  - 0.4.0-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jan 19 2023 Fedora Release Engineering  - 0.4.0-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1980774 - libeconf-0.5.2 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1980774
  [ 2 ] Bug #2212464 - CVE-2023-22652 libeconf: stack-based buffer overflow in read_file() in lib/getfilecontents.c [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2212464
  [ 3 ] Bug #2235236 - CVE-2023-30079 libeconf: Stack overflow in function read_file at atlibeconf/lib/getfilecontents.c [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2235236
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2023-b4b77f950c' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/
Do not reply to spam, report it: https://pagure.io/login/

Fedora 37: libeconf 2023-b4b77f950c

September 13, 2023
Rebase to 0.5.2 to fix CVE-2023-22652 and CVE-2023-30079

Summary

libeconf is a highly flexible and configurable library to parse and manage

key=value configuration files. It reads configuration file snippets from

different directories and builds the final configuration file from it.

Update Information:

Rebase to 0.5.2 to fix CVE-2023-22652 and CVE-2023-30079

Change Log

* Mon Aug 28 2023 Iker Pedrosa - 0.5.2-1 - Update to 0.5.2 (RH#1980774) - Fix CVE-2023-22652 (RH#2212464) - Fix CVE-2023-30079 (RH#2235236) * Thu Jul 20 2023 Fedora Release Engineering - 0.4.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Jan 19 2023 Fedora Release Engineering - 0.4.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild

References

[ 1 ] Bug #1980774 - libeconf-0.5.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1980774 [ 2 ] Bug #2212464 - CVE-2023-22652 libeconf: stack-based buffer overflow in read_file() in lib/getfilecontents.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2212464 [ 3 ] Bug #2235236 - CVE-2023-30079 libeconf: Stack overflow in function read_file at atlibeconf/lib/getfilecontents.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2235236

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-b4b77f950c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
Name : libeconf
Product : Fedora 37
Version : 0.5.2
Release : 1.fc37
URL : https://github.com/openSUSE/libeconf
Summary : Enhanced config file parser library

Related News