Ubuntu 6964-1: ORC Security Advisory Updates
Summary
A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: ORC could be made to crash or execute arbitrary code Software Description: - orc: Library of Optimized Inner Loops Runtime Compiler Details: Noriko Totsuka discovered that ORC incorrectly handled certain crafted file. An attacker could possibly use this issue to execute arbitrary code.
Update Instructions
The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS liborc-0.4-0t64 1:0.4.38-1ubuntu0.1 Ubuntu 22.04 LTS liborc-0.4-0 1:0.4.32-2ubuntu0.1 Ubuntu 20.04 LTS liborc-0.4-0 1:0.4.31-1ubuntu0.1 In general, a standard system update will make all the necessary changes.
References
https://ubuntu.com/security/notices/USN-6964-1
CVE-2024-40897
Package Information
https://launchpad.net/ubuntu/+source/orc/1:0.4.38-1ubuntu0.1 https://launchpad.net/ubuntu/+source/orc/1:0.4.32-2ubuntu0.1 https://launchpad.net/ubuntu/+source/orc/1:0.4.31-1ubuntu0.1