Ubuntu alert USN-7316-1 (raptor2)
From: | Marc Deslauriers <marc.deslauriers@canonical.com> | |
To: | "ubuntu-security-announce@lists.ubuntu.com" <ubuntu-security-announce@lists.ubuntu.com> | |
Subject: | [USN-7316-1] Raptor vulnerabilities | |
Date: | Mon, 03 Mar 2025 12:24:44 -0500 | |
Message-ID: | <cbde272b-629c-4fb1-805e-16e7bdd3e89f@canonical.com> |
========================================================================== Ubuntu Security Notice USN-7316-1 March 03, 2025 raptor2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in Raptor. Software Description: - raptor2: RDF syntax library Details: It was discovered that Raptor incorrectly handled memory operations when processing certain input files. A remote attacker could possibly use this issue to cause Raptor to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-25713) It was discovered that Raptor incorrectly handled parsing certain tuples. A remote attacker could possibly use this issue to cause Raptor to crash, resulting in a denial of service. (CVE-2024-57822) It was discovered that Raptor incorrectly handled parsing certain turtles. A remote attacker could use this issue to cause Raptor to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2024-57823) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 libraptor2-0 2.0.16-4ubuntu0.1 raptor2-utils 2.0.16-4ubuntu0.1 Ubuntu 24.04 LTS libraptor2-0 2.0.16-3ubuntu0.1 raptor2-utils 2.0.16-3ubuntu0.1 Ubuntu 22.04 LTS libraptor2-0 2.0.15-0ubuntu4.1 raptor2-utils 2.0.15-0ubuntu4.1 Ubuntu 20.04 LTS libraptor2-0 2.0.15-0ubuntu1.20.04.2 raptor2-utils 2.0.15-0ubuntu1.20.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7316-1 CVE-2020-25713, CVE-2024-57822, CVE-2024-57823 Package Information: https://launchpad.net/ubuntu/+source/raptor2/2.0.16-4ubun... https://launchpad.net/ubuntu/+source/raptor2/2.0.16-3ubun... https://launchpad.net/ubuntu/+source/raptor2/2.0.15-0ubun... https://launchpad.net/ubuntu/+source/raptor2/2.0.15-0ubun...
Attachment: OpenPGP_signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- wsF5BAABCAAjFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmfF5dwFAwAAAAAACgkQZWnYVadEvpNt eBAAhi/3RbqkrXPbD/Y0HFKGMIJJ4iikp3vpV/IVMSZ7UHNrHl+B5tTRxx4FaWkG0+y4Ql66CHeD vAyiOeWfayDpQ/V0CjEY3oxf2/+zUkS/5QZiRhJO9OTGVCIvftIOhCTpCVTIkhSNPxjRVHAlbWga tr/ndrwYUMcvUj6WOctTex8Knckf+SL5bGAw95J391mmLTzbnC62dgF+5qhcfLPwJBsHNocMcYN7 GixfORTgknhEbJ5C2bUnA62sNqU0mqFEZDVYBYvZfevM3XZLgn2uStC4gUfZ8iWAzLKbfwYPEmsO ewhgklOogd2H0T0+zTaGent0zNa0vsRJECh0m0jQO1Eqaf1Y3vSLni7gMAxRO6OZzBCvq59ajODw j5fHqqLlzvBv3FfqlVnzfTN+4n/+XZrWHyR+xjfvJygv7QGHeo3+AytNeEfY6k7DxsSzWwwo56C+ YJSsf/BQ+4sXAD4+WptzZTizGdoTdSklr/k1lwm/wAg7NSFH3n9JB2e9M00EFUN7cM/SnMzToZyM ZkNGlU6TLbJE/RPirGEFxFF8/N6qcIgivgafqoGbi+ouIbz8C7nbyuw/5H/WOzj72sOgRhyf6fCN u4LPtTgH++0Q3OGXlJqjqbFgWv8jXsBdyj+RlZyjzD4JSjbDQIXAXM/wzQFd4A5C8C+gbo9995ej zbE= =hvFZ -----END PGP SIGNATURE-----
Attachment: None (type=text/plain)