UbuntuUpdates.org

Package "libproc2-dev"

Name: libproc2-dev

Description:

library for accessing process information from /proc

Latest version: 2:4.0.3-1ubuntu1.23.10.1
Release: mantic (23.10)
Level: updates
Repository: main
Head package: procps
Homepage: https://gitlab.com/procps-ng/procps

Links


Download "libproc2-dev"


Other versions of "libproc2-dev" in Mantic

Repository Area Version
base main 2:4.0.3-1ubuntu1
security main 2:4.0.3-1ubuntu1.23.10.1

Changelog

Version: 2:4.0.3-1ubuntu1.23.10.1 2023-11-14 12:09:24 UTC

  procps (2:4.0.3-1ubuntu1.23.10.1) mantic-security; urgency=medium

  * SECURITY UPDATE: heap-based buffer overflow
    - debian/patches/CVE-2023-4016.patch: replace the use of malloc() with calloc()
      in ps/parser.c to prevent the potential for an arithmetic overflow when
      allocating memory.
    - CVE-2023-4016

 -- Ian Constantin <email address hidden> Mon, 06 Nov 2023 14:12:55 +0200

CVE-2023-4016 Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amou



About   -   Send Feedback to @ubuntu_updates