{"id":"MGASA-2024-0288","summary":"Updated orc packages fix security vulnerability","details":"Stack-based buffer overflow vulnerability exists in orcparse.c of ORC\nversions prior to 0.4.39. If a developer is tricked to process a\nspecially crafted file with the affected ORC compiler, an arbitrary code\nmay be executed on the developer's build environment. This may lead to\ncompromise of developer machines or CI build environments.\n(CVE-2024-40897)\n","modified":"2026-04-16T04:41:57.505552332Z","published":"2024-09-10T16:40:31Z","upstream":["CVE-2024-40897"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0288.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33529"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6964-1"}],"affected":[{"package":{"name":"orc","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/orc?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.33-1.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0288.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}