--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2023-f5680e3b4b
2023-09-18 01:37:07.642176
--------------------------------------------------------------------------------

Name        : libtommath
Product     : Fedora 37
Version     : 1.2.0
Release     : 11.fc37
URL         : https://www.libtom.net/
Summary     : A portable number theoretic multiple-precision integer library
Description :
A free open source portable number theoretic multiple-precision integer library
written entirely in C. (phew!). The library is designed to provide a simple to
work with API that provides fairly efficient routines that build out of the box
without configuration.

--------------------------------------------------------------------------------
Update Information:

Security fix for CVE-2023-36328
--------------------------------------------------------------------------------
ChangeLog:

* Sat Sep  2 2023 Frantisek Sumsal  - 1.2.0-11
- Fix CVE-2023-36328 (#2236877,#2236878)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2236877 - CVE-2023-36328 libtommath: Integer Overflow vulnerability in mp_grow in libtom
        https://bugzilla.redhat.com/show_bug.cgi?id=2236877
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2023-f5680e3b4b' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/
Do not reply to spam, report it: https://pagure.io/login/

Fedora 37: libtommath 2023-f5680e3b4b

September 18, 2023
Security fix for CVE-2023-36328

Summary

A free open source portable number theoretic multiple-precision integer library

written entirely in C. (phew!). The library is designed to provide a simple to

work with API that provides fairly efficient routines that build out of the box

without configuration.

Update Information:

Security fix for CVE-2023-36328

Change Log

* Sat Sep 2 2023 Frantisek Sumsal - 1.2.0-11 - Fix CVE-2023-36328 (#2236877,#2236878)

References

[ 1 ] Bug #2236877 - CVE-2023-36328 libtommath: Integer Overflow vulnerability in mp_grow in libtom https://bugzilla.redhat.com/show_bug.cgi?id=2236877

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-f5680e3b4b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
Name : libtommath
Product : Fedora 37
Version : 1.2.0
Release : 11.fc37
URL : https://www.libtom.net/
Summary : A portable number theoretic multiple-precision integer library

Related News