Stack-based buffer overflow in Orc - CVE-2024-40897
Published: July 19, 2024 / Updated: July 29, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when compiling orc files. A remote attacker can trick the victim into compiling a malicious source code file, trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux Server - AUS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Package Hub 15
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Rapid Infrastructure Automation
liborc-0.4-dev (Ubuntu package)
liborc-0.4-0 (Ubuntu package)
orc-debugsource
liborc-0_4-0-debuginfo-32bit
liborc-0_4-0-32bit
liborc-0_4-0
orc-debuginfo
orc
liborc-0_4-0-debuginfo
orc-compiler
orc-devel
orc-doc
orc (Red Hat package)
liborc-0_4-0-32bit-debuginfo
orc-help
liborc-0.4-0t64 (Ubuntu package)
dev-lang/orc
Red Hat OpenShift Container Platform
App Connect Enterprise Certified Container
IBM Observability with Instana
How to mitigate CVE-2024-40897
Rapid Infrastructure Automation - update to 1.1.5.3
liborc-0.4-dev (Ubuntu package) - update to Ubuntu Pro
liborc-0.4-0 (Ubuntu package) - addressed in versions Ubuntu Pro, 1:0.4.31-1ubuntu0.1, 1:0.4.32-2ubuntu0.1
orc-debugsource - addressed in versions 0.4.21-3.3.1, 0.4.21-3.6.1, 0.4.28-150000.3.6.1, 0.4.28-150000.3.9.1
liborc-0_4-0-debuginfo-32bit - addressed in versions 0.4.21-3.3.1, 0.4.21-3.6.1
liborc-0_4-0-32bit - addressed in versions 0.4.21-3.3.1, 0.4.21-3.6.1, 0.4.28-150000.3.6.1, 0.4.28-150000.3.9.1
liborc-0_4-0 - addressed in versions 0.4.21-3.3.1, 0.4.21-3.6.1, 0.4.28-150000.3.6.1, 0.4.28-150000.3.9.1
orc-debuginfo - addressed in versions 0.4.21-3.3.1, 0.4.21-3.6.1, 0.4.28-150000.3.6.1, 0.4.28-150000.3.9.1
orc - addressed in versions 0.4.21-3.3.1, 0.4.28-150000.3.6.1, 0.4.28-150000.3.9.1
liborc-0_4-0-debuginfo - addressed in versions 0.4.21-3.3.1, 0.4.21-3.6.1, 0.4.28-150000.3.6.1, 0.4.28-150000.3.9.1
orc-compiler - addressed in versions 0.4.28-4, 0.4.39-1
orc - addressed in versions 0.4.28-4, 0.4.39-1
orc-devel - addressed in versions 0.4.28-4, 0.4.39-1
orc-doc - addressed in versions 0.4.28-4, 0.4.39-1
orc (Red Hat package) - update to 0.4.28-4.el8_2
orc-doc - addressed in versions 0.4.28-150000.3.6.1, 0.4.28-150000.3.9.1
liborc-0_4-0-32bit-debuginfo - addressed in versions 0.4.28-150000.3.6.1, 0.4.28-150000.3.9.1
orc-help - update to 0.4.34-2
orc-devel - update to 0.4.34-2
orc - update to 0.4.34-2
orc-compiler - update to 0.4.34-2
orc-debuginfo - update to 0.4.34-2
orc-debugsource - update to 0.4.34-2
liborc-0.4-0t64 (Ubuntu package) - update to 1:0.4.38-1ubuntu0.1
orc - update to 0.4.39-1.fc40
dev-lang/orc - update to 0.4.40
Red Hat OpenShift Container Platform - update to 4.13.48
App Connect Enterprise Certified Container - addressed in versions 5.0.21, 12.0.4, 12.4.0
IBM Observability with Instana - update to 284
External References
Related Security Bulletins
- Remote code execution in GStreamer Orc compiler
- SUSE update for orc
- SUSE update for orc
- Fedora 40 update for orc
- openEuler update for orc
- Ubuntu update for orc
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Red Hat Enterprise Linux 8 update for the orc:0.4.28 module
- Ubuntu update for orc
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in IBM Observability with Instana
- SUSE update for orc
- SUSE update for orc
- Anolis OS update for orc
- Gentoo update for Orc
- Multiple vulnerabilities in IBM Rapid Infrastructure Automation
- Anolis OS update for orc