ALAS-2024-633


Amazon Linux 2023 Security Advisory: ALAS-2024-633
Advisory Release Date: 2024-05-23 21:49 Pacific
Advisory Updated Date: 2024-05-28 22:45 Pacific
Severity: Medium

Issue Overview:

In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink. (CVE-2022-48682)


Affected Packages:

fdupes


Issue Correction:
Run dnf update fdupes --releasever 2023.4.20240528 to update your system.

New Packages:
aarch64:
    fdupes-debuginfo-2.3.0-1.amzn2023.aarch64
    fdupes-debugsource-2.3.0-1.amzn2023.aarch64
    fdupes-2.3.0-1.amzn2023.aarch64

src:
    fdupes-2.3.0-1.amzn2023.src

x86_64:
    fdupes-debuginfo-2.3.0-1.amzn2023.x86_64
    fdupes-2.3.0-1.amzn2023.x86_64
    fdupes-debugsource-2.3.0-1.amzn2023.x86_64