-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-450b75e4a0 2024-05-03 01:25:18.628875 --------------------------------------------------------------------------------
Name : libcoap Product : Fedora 39 Version : 4.3.4a Release : 2.fc39 URL : https://libcoap.net/ Summary : C library implementation of CoAP Description : The Constrained Application Protocol (CoAP) is a specialized web transfer protocol for use with constrained nodes and constrained networks in the Internet of Things. The protocol is designed for machine-to-machine (M2M) applications such as smart energy and building automation.
libcoap implements a lightweight application-protocol for devices with constrained resources such as computing power, RF range, memory, bandwidth, or network packet sizes. This protocol, CoAP, was standardized in the IETF working group "CoRE" as RFC 7252.
-------------------------------------------------------------------------------- Update Information:
Patch to fix CVE-2024-31031 -------------------------------------------------------------------------------- ChangeLog:
* Wed Apr 24 2024 Peter Robinson pbrobinson@fedoraproject.org - 4.3.4a-2 - Patch to fix CVE-2024-31031 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #2275804 - CVE-2024-31031 libcoap: unsigned integer overflow vulnerability in coap_pdu.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2275804 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-450b75e4a0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------
package-announce@lists.fedoraproject.org