Headline
Ubuntu Security Notice USN-6389-1
Ubuntu Security Notice 6389-1 - It was discovered that Indent incorrectly handled parsing certain source files. If a user or automated system were tricked into processing a specially crafted source file, a remote attacker could use this issue to cause Indent to crash, resulting in a denial of service, or possibly execute arbitrary code.
==========================================================================Ubuntu Security Notice USN-6389-1September 20, 2023indent vulnerability==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 23.04- Ubuntu 22.04 LTS- Ubuntu 20.04 LTSSummary:Indent could be made to crash or run programs if it opened a speciallycrafted file.Software Description:- indent: C language source code formatting programDetails:It was discovered that Indent incorrectly handled parsing certain sourcefiles. If a user or automated system were tricked into processing aspecially crafted source file, a remote attacker could use this issue tocause Indent to crash, resulting in a denial of service, or possiblyexecute arbitrary code.Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 23.04: indent 2.2.12-4ubuntu0.1Ubuntu 22.04 LTS: indent 2.2.12-1ubuntu0.22.04.1Ubuntu 20.04 LTS: indent 2.2.12-1ubuntu0.20.04.1In general, a standard system update will make all the necessary changes.References: https://ubuntu.com/security/notices/USN-6389-1 CVE-2023-40305Package Information: https://launchpad.net/ubuntu/+source/indent/2.2.12-4ubuntu0.1 https://launchpad.net/ubuntu/+source/indent/2.2.12-1ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/indent/2.2.12-1ubuntu0.20.04.1
Related news
CVE-2023-40305: Index of /gnu/indent
GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file.