UbuntuUpdates.org

Package "adsys"

Name: adsys

Description:

AD SYStem integration

Latest version: 0.15.2ubuntu0.1
Release: oracular (24.10)
Level: security
Repository: main
Homepage: https://github.com/ubuntu/adsys

Links


Download "adsys"


Other versions of "adsys" in Oracular

Repository Area Version
base universe 0.15.2
base main 0.15.2
security universe 0.15.2ubuntu0.1
updates main 0.15.2ubuntu0.1
updates universe 0.15.2ubuntu0.1
proposed main 0.16.3~24.10
proposed universe 0.16.3~24.10

Changelog

Version: 0.15.2ubuntu0.1 2025-01-09 17:07:26 UTC

  adsys (0.15.2ubuntu0.1) oracular-security; urgency=medium

  * SECURITY UPDATE: Denial of service in parse function.
    - Use strings.EqualFold instead of direct comparison and
      strings.ToLower in .../html/doctype.go, .../html/foreign.go, and
      .../html/parse.go. Based on
      https://go.googlesource.com/net/+/8e66b04771e35c4e4125e8c60334b34e2423effb
      upstream patch.
    - CVE-2024-45338

 -- Hlib Korzhynskyy <email address hidden> Tue, 07 Jan 2025 14:39:21 -0330

CVE-2024-45338 An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow pa



About   -   Send Feedback to @ubuntu_updates