#1033255 aflplusplus: CVE-2023-26266

Package:
src:aflplusplus
Source:
src:aflplusplus
Submitter:
Moritz Mühlenhoff
Date:
2023-03-24 13:21:03 UTC
Severity:
normal
Tags:
#1033255#5
Date:
2023-03-20 19:12:36 UTC
From:
To:
Hi,

The following vulnerability was published for aflplusplus.

CVE-2023-26266[0]:
| In AFL++ 4.05c, the CmpLog component uses the current working
| directory to resolve and execute unprefixed fuzzing targets, allowing
| code execution.

https://github.com/AFLplusplus/AFLplusplus/pull/1643
https://github.com/AFLplusplus/AFLplusplus/commit/f2be73186e2e16c3992f92b65ae9ba598d6fff2f
https://github.com/AFLplusplus/AFLplusplus/commit/673a0a3866783bf28e31d14fbd7a9009c7816ec3


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-26266
https://www.cve.org/CVERecord?id=CVE-2023-26266

Please adjust the affected versions in the BTS as needed.

#1033255#12
Date:
2023-03-24 12:54:50 UTC
From:
To:
Hello,

Bug #1033255 in aflplusplus reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/pkg-security-team/aflplusplus/-/commit/297fb08d66cde36c3f252e08d40dfc0152c420ca

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1033255

#1033255#19
Date:
2023-03-24 13:19:07 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
aflplusplus, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1033255@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sophie Brun <sophie@offensive-security.com> (supplier of updated aflplusplus package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 24 Mar 2023 11:29:28 +0100
Source: aflplusplus
Architecture: source
Version: 4.04c-4
Distribution: unstable
Urgency: medium
Maintainer: Debian Security Tools <team+pkg-security@tracker.debian.org>
Changed-By: Sophie Brun <sophie@offensive-security.com>
Closes: 1033255
Changes:
 aflplusplus (4.04c-4) unstable; urgency=medium
 .
   * Import a patch to fix CVE-2023-26266 (Closes: #1033255)
Checksums-Sha1:
 dc425c5fcb43811d3f71ba44e95f8f8ba2c52378 2496 aflplusplus_4.04c-4.dsc
 0212793cd3be821733cb18434265460c365a2734 11548 aflplusplus_4.04c-4.debian.tar.xz
 f93ad461345a188d8224f128a3fe6f0288533115 8732 aflplusplus_4.04c-4_source.buildinfo
Checksums-Sha256:
 5c005ead4945ea4645ef4c3c18c99944f87c8311ecbaf061ee44751c3390fa3b 2496 aflplusplus_4.04c-4.dsc
 c87abd29e2e79fb6c71c2766b350c1d435c24771da62e2bbfe096e9d94015acd 11548 aflplusplus_4.04c-4.debian.tar.xz
 8f3558507f0b11c154bef23cfebaad5a04f87d5a5631ab74806a7c2e015918f7 8732 aflplusplus_4.04c-4_source.buildinfo
Files:
 4d5e86bab4d08b8a29be18f1d383cb27 2496 devel optional aflplusplus_4.04c-4.dsc
 391c928a6564834800744af39b58f4d3 11548 devel optional aflplusplus_4.04c-4.debian.tar.xz
 8f94ba297b5137da0be8ba13181d4aff 8732 devel optional aflplusplus_4.04c-4_source.buildinfo
iQIzBAEBCgAdFiEEOyG45orlwW+H9TItV5J4OyBv7jAFAmQdnXYACgkQV5J4OyBv
7jBY9g/8Dm+FyLoU+AR0NpffvjTerVw6oPkau0gab/74yG0hRp+wEDcDus5G5tPo
P9Z/eJecsR2y/mEiSkGRYsuJClCsQvvw6fDDs9E+wzuNZRbGduLNxFVbkioMGkKn
+iMXDRQHh9m9aWDN7o8ZZKidqR8X0RhHfPnvqQjhTje8Mka72kL/kEBuPd2BbWrr
BR9R0m5l+HCKaeWrI6ymeTVY4k4+cbzrfijJHl67AHwVqN2qULr8SgRqfZluPbi6
/OzEzXlw05c/pnOHO2/5GMcE4/aUJ6PGvWiB2vZZnX5cu3dIxia6hn361WyPUmqe
vfEeV+8cWfogPeC1Snu1xStUlx/+tWE63Q+5pBI/4XH5ksFnc9bBLnwZzjrpthT9
8nsU0wjsRjcZEpEOLnJ1TinZoyPV2ixP3cw+OyzTcY5tq/foUy2HjWPwMxz11MO7
AwmVfxD/7IvO4ryZGJdWiEBJTBs3PRPEzk4VsZL/KtvSMWUAGqJmNrLHjgr2KMwZ
RxQMOVsVhIbqsjwE3pCYHGRHWZknmKkXV87/pnd42MABexVOhyuU3KFpwixaAZPW
Hf4DJ301tUR9d3MUeXhhUuVzceP2KUU/sRHKVxOS1xEo3cP/VSb37CQfzIJ1y8sK
po7UC31MNfkbcDccRjxiBurWOyc6XQ1QU+18vAW5cgGJC5SGknk=
=dDVk
-----END PGP SIGNATURE-----