ALAS-2023-2343


Amazon Linux 2 Security Advisory: ALAS-2023-2343
Advisory Release Date: 2023-11-09 19:19 Pacific
Advisory Updated Date: 2023-11-15 21:09 Pacific
Severity: Medium

Issue Overview:

A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way. (CVE-2022-4515)


Affected Packages:

ctags


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update ctags to update your system.

New Packages:
aarch64:
    ctags-5.8-23.amzn2.aarch64
    ctags-etags-5.8-23.amzn2.aarch64
    ctags-debuginfo-5.8-23.amzn2.aarch64

i686:
    ctags-5.8-23.amzn2.i686
    ctags-etags-5.8-23.amzn2.i686
    ctags-debuginfo-5.8-23.amzn2.i686

src:
    ctags-5.8-23.amzn2.src

x86_64:
    ctags-5.8-23.amzn2.x86_64
    ctags-etags-5.8-23.amzn2.x86_64
    ctags-debuginfo-5.8-23.amzn2.x86_64