Skip to content

0.32.0

Compare
Choose a tag to compare
@cf-buildpacks-eng cf-buildpacks-eng released this 22 Sep 16:31
· 335 commits to main since this release

Notably, this release addresses:

USN-5627-1 USN-5627-1: PCRE vulnerabilities:

  • CVE-2022-1586: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.
  • CVE-2022-1587: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
-ii  bind9-dnsutils              1:9.18.1-1ubuntu1.1 amd64 Clients provided with BIND 9
-ii  bind9-host                  1:9.18.1-1ubuntu1.1 amd64 DNS Lookup Utility
-ii  bind9-libs:amd64            1:9.18.1-1ubuntu1.1 amd64 Shared Libraries used by BIND 9
+ii  bind9-dnsutils              1:9.18.1-1ubuntu1.2 amd64 Clients provided with BIND 9
+ii  bind9-host                  1:9.18.1-1ubuntu1.2 amd64 DNS Lookup Utility
+ii  bind9-libs:amd64            1:9.18.1-1ubuntu1.2 amd64 Shared Libraries used by BIND 9
-ii  dnsutils                    1:9.18.1-1ubuntu1.1 all   Transitional package for bind9-dnsutils
+ii  dnsutils                    1:9.18.1-1ubuntu1.2 all   Transitional package for bind9-dnsutils
-ii  gzip                        1.10-4ubuntu4       amd64 GNU compression utilities
+ii  gzip                        1.10-4ubuntu4.1     amd64 GNU compression utilities
-ii  libpcre2-16-0:amd64         10.39-3build1       amd64 New Perl Compatible Regular Expression Library - 16 bit runtime files
-ii  libpcre2-32-0:amd64         10.39-3build1       amd64 New Perl Compatible Regular Expression Library - 32 bit runtime files
-ii  libpcre2-8-0:amd64          10.39-3build1       amd64 New Perl Compatible Regular Expression Library- 8 bit runtime files
-ii  libpcre2-dev:amd64          10.39-3build1       amd64 New Perl Compatible Regular Expression Library - development files
-ii  libpcre2-posix3:amd64       10.39-3build1       amd64 New Perl Compatible Regular Expression Library - posix-compatible runtime files
+ii  libpcre2-16-0:amd64         10.39-3ubuntu0.1    amd64 New Perl Compatible Regular Expression Library - 16 bit runtime files
+ii  libpcre2-32-0:amd64         10.39-3ubuntu0.1    amd64 New Perl Compatible Regular Expression Library - 32 bit runtime files
+ii  libpcre2-8-0:amd64          10.39-3ubuntu0.1    amd64 New Perl Compatible Regular Expression Library- 8 bit runtime files
+ii  libpcre2-dev:amd64          10.39-3ubuntu0.1    amd64 New Perl Compatible Regular Expression Library - development files
+ii  libpcre2-posix3:amd64       10.39-3ubuntu0.1    amd64 New Perl Compatible Regular Expression Library - posix-compatible runtime files
-ii  libpython3-stdlib:amd64     3.10.4-0ubuntu2     amd64 interactive high-level object-oriented language (default python3 version)
-ii  libpython3.10:amd64         3.10.4-3ubuntu0.1   amd64 Shared Python runtime library (version 3.10)
-ii  libpython3.10-minimal:amd64 3.10.4-3ubuntu0.1   amd64 Minimal subset of the Python language (version 3.10)
-ii  libpython3.10-stdlib:amd64  3.10.4-3ubuntu0.1   amd64 Interactive high-level object-oriented language (standard library, version 3.10)
+ii  libpython3-stdlib:amd64     3.10.6-1~22.04      amd64 interactive high-level object-oriented language (default python3 version)
+ii  libpython3.10:amd64         3.10.6-1~22.04      amd64 Shared Python runtime library (version 3.10)
+ii  libpython3.10-minimal:amd64 3.10.6-1~22.04      amd64 Minimal subset of the Python language (version 3.10)
+ii  libpython3.10-stdlib:amd64  3.10.6-1~22.04      amd64 Interactive high-level object-oriented language (standard library, version 3.10)
-ii  libsystemd0:amd64           249.11-0ubuntu3.4   amd64 systemd utility library
+ii  libsystemd0:amd64           249.11-0ubuntu3.6   amd64 systemd utility library
-ii  libudev1:amd64              249.11-0ubuntu3.4   amd64 libudev shared library
+ii  libudev1:amd64              249.11-0ubuntu3.6   amd64 libudev shared library
-ii  python3                     3.10.4-0ubuntu2     amd64 interactive high-level object-oriented language (default python3 version)
+ii  python3                     3.10.6-1~22.04      amd64 interactive high-level object-oriented language (default python3 version)
-ii  python3-distutils           3.10.4-0ubuntu1     all   distutils package for Python 3.x
+ii  python3-distutils           3.10.6-1~22.04      all   distutils package for Python 3.x
-ii  python3-lib2to3             3.10.4-0ubuntu1     all   Interactive high-level object-oriented language (lib2to3)
-ii  python3-minimal             3.10.4-0ubuntu2     amd64 minimal subset of the Python language (default python3 version)
+ii  python3-lib2to3             3.10.6-1~22.04      all   Interactive high-level object-oriented language (lib2to3)
+ii  python3-minimal             3.10.6-1~22.04      amd64 minimal subset of the Python language (default python3 version)
-ii  python3.10                  3.10.4-3ubuntu0.1   amd64 Interactive high-level object-oriented language (version 3.10)
-ii  python3.10-minimal          3.10.4-3ubuntu0.1   amd64 Minimal subset of the Python language (version 3.10)
+ii  python3.10                  3.10.6-1~22.04      amd64 Interactive high-level object-oriented language (version 3.10)
+ii  python3.10-minimal          3.10.6-1~22.04      amd64 Minimal subset of the Python language (version 3.10)
-ii  systemd                     249.11-0ubuntu3.4   amd64 system and service manager
-ii  systemd-sysv                249.11-0ubuntu3.4   amd64 system and service manager - SysV links
+ii  systemd                     249.11-0ubuntu3.6   amd64 system and service manager
+ii  systemd-sysv                249.11-0ubuntu3.6   amd64 system and service manager - SysV links
-ii  udev                        249.11-0ubuntu3.4   amd64 /dev/ and hotplug management daemon
+ii  udev                        249.11-0ubuntu3.6   amd64 /dev/ and hotplug management daemon