{"id":"MGASA-2024-0241","summary":"Updated erofs-utils packages fix security vulnerabilities","details":"Heap Buffer Overflow in the erofsfsck_dirent_iter function in\nfsck/main.c in erofs-utils v1.6 allows remote attackers to execute\narbitrary code via a crafted erofs filesystem image.\n","modified":"2026-04-16T04:40:34.953806117Z","published":"2024-06-28T02:41:31Z","upstream":["CVE-2023-33551","CVE-2023-33552"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0241.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=32272"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FHOIRL6XH5NYR3LYI3KP5DE4SDSQWR7W/"}],"affected":[{"package":{"name":"erofs-utils","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/erofs-utils?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.1-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0241.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}