Amazon Linux 2023 Security Advisory: ALAS-2024-633
Advisory Release Date: 2024-05-23 21:49 Pacific
Advisory Updated Date: 2024-05-28 22:45 Pacific
In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink. (CVE-2022-48682)
Affected Packages:
fdupes
Issue Correction:
Run dnf update fdupes --releasever 2023.4.20240528 to update your system.
aarch64:
fdupes-debuginfo-2.3.0-1.amzn2023.aarch64
fdupes-debugsource-2.3.0-1.amzn2023.aarch64
fdupes-2.3.0-1.amzn2023.aarch64
src:
fdupes-2.3.0-1.amzn2023.src
x86_64:
fdupes-debuginfo-2.3.0-1.amzn2023.x86_64
fdupes-2.3.0-1.amzn2023.x86_64
fdupes-debugsource-2.3.0-1.amzn2023.x86_64