-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Migration Toolkit for Runtimes security update Advisory ID: RHSA-2023:3374-01 Product: Migration Toolkit for Runtimes Advisory URL: https://access.redhat.com/errata/RHSA-2023:3374 Issue date: 2023-05-31 CVE Names: CVE-2022-37603 CVE-2022-41881 ===================================================================== 1. Summary: Migration Toolkit for Runtimes 1.1.0 release Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Migration Toolkit for Runtimes 1.1.0 ZIP artifacts Security Fix(es): * loader-utils: Regular expression denial of service (CVE-2022-37603) * codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS (CVE-2022-41881) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2140597 - CVE-2022-37603 loader-utils:Regular expression denial of service 2153379 - CVE-2022-41881 codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS 5. References: https://access.redhat.com/security/cve/CVE-2022-37603 https://access.redhat.com/security/cve/CVE-2022-41881 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=migration.toolkit.runtimes&downloadType=distributions 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZHsCbdzjgjWX9erEAQjmKg/+JdODxrKY7Y7MNYtIWlDNWkLW/H+spNql bl+h7icTnTiBgbeCXEl9/g8C6HLJZHJ2nYj+av5qSV3kgbYLyLexa6SiY/dd/fCB XpPmWFaOx9i2yYtGXMsDLUc0OAW2mE4Z7F9VuiXuJyU6BtMIOeQ2DR+SfFZ3RpSR 5W1SCUiR2FnNIqyAteTZ6CEQKa7VbZGMUdW1oBhFqN0ThThIY7Ao+BBmspnQtMUW JakuaYwW6qbEtEnKxhhYi598e0X5Mkv2eNnXKkWpE9r6kzLp+RlerRDzvxNFFa2H Wu3mGWzx4sA9/7YxAu13PS9185WISUHeWr022M2JWJzcV/tN67F0N3QgYsGH+gyb pHpcFRg5V/m/xlOhZuz8a0d0IfbRqgd3F32b0LaYpw7rSrfz5+9KeHVCM9aU9hII Wn3+sHlIIGdlnWGGKCXuLiDIqVyaqDzb/a3HgQ3JHSE5vWyTQ19CFUYotrx4EjTH FgbPyou4IOfcoNS5oPRFTFCG0OMSdAOYwFv0G4kIKTf/PLHPGnK+0+8htKmXbb0S lugcu/oGz/ultxYSGiOivh8B6Wk9AXoulxV3iZBjTUacBSyaHUAQ86t6GN+RHCqs 6ydFkk/Qw9oflGbndDMELaThIzHZXFg6UoOSMb4dDmBiU/FFL7ab1p9MslGjIAh5 3KmwYDRd4d0= =Ev0R -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce