Amazon Linux 2023 Security Advisory: ALAS-2024-655
Advisory Release Date: 2024-07-18 01:24 Pacific
Advisory Updated Date: 2024-07-22 16:00 Pacific
dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohmann` JSON library. However, due to the way the JSON library is invoked, it throws an uncaught exception, which results in a crash. This vulnerability has been patched in version 0.2.2. (CVE-2024-38525)
Affected Packages:
ecs-service-connect-agent
Issue Correction:
Run dnf update ecs-service-connect-agent --releasever 2023.5.20240722 to update your system.
aarch64:
ecs-service-connect-agent-v1.29.6.0-1.amzn2023.aarch64
src:
ecs-service-connect-agent-v1.29.6.0-1.amzn2023.src
x86_64:
ecs-service-connect-agent-v1.29.6.0-1.amzn2023.x86_64