| Summary: | miniupnpc new security issue CVE-2015-6031 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | davidwhodgins, rverschelde, sysadmin-bugs, wilcal.int |
| Version: | 5 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/661346/ | ||
| Whiteboard: | advisory MGA5-64-OK | ||
| Source RPM: | miniupnpc-1.9.20141128-1.mga5.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2015-10-19 18:31:23 CEST
Dave Hodgins
2015-10-25 23:29:27 CET
CC:
(none) =>
davidwhodgins In VirtualBox, M5, KDE, 32-bit Package(s) under test: miniupnpc libminiupnpc12 megaglest default install of miniupnpc libminiupnpc12 & megaglest [root@localhost wilcal]# urpmi miniupnpc Package miniupnpc-1.9.20141128-1.mga5.i586 is already installed [root@localhost wilcal]# urpmi libminiupnpc12 Package libminiupnpc12-1.9.20141128-1.mga5.i586 is already installed [root@localhost wilcal]# urpmi megaglest Package megaglest-3.11.1-1.1.mga5.i586 is already installed megaglest crashes on launch. Just like it did in 13374. libGL error. Installed cleanly. install miniupnpc & libminiupnpc12 from updates_testing [root@localhost wilcal]# urpmi miniupnpc Package miniupnpc-1.9.20141128-1.1.mga5.i586 is already installed [root@localhost wilcal]# urpmi libminiupnpc12 Package libminiupnpc12-1.9.20141128-1.1.mga5.i586 is already installed Installs cleanly CC:
(none) =>
wilcal.int In VirtualBox, M5, KDE, 64-bit Package(s) under test: miniupnpc lib64miniupnpc12 megaglest default install of miniupnpc libminiupnpc12 & megaglest [root@localhost wilcal]# urpmi miniupnpc Package miniupnpc-1.9.20141128-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi lib64miniupnpc12 Package lib64miniupnpc12-1.9.20141128-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi megaglest Package megaglest-3.11.1-1.1.mga5.x86_64 is already installed megaglest crashes on launch. Just like it did in 13374. libGL error. Installed cleanly. install miniupnpc & lib64miniupnpc12 from updates_testing [root@localhost wilcal]# urpmi miniupnpc Package miniupnpc-1.9.20141128-1.1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi lib64miniupnpc12 Package lib64miniupnpc12-1.9.20141128-1.1.mga5.x86_64 is already installed Installs cleanly Move it along just like we did last time? $ urpmq --whatrequires lib64miniupnpc12 0ad bitcoin-qt bitcoind dogecoin-qt dogecoind dolphin-emu dolphin-emu lib64eiskaltdcpp2.2 lib64miniupnpc-devel lib64miniupnpc12 megaglest megaglest miniupnpc Could try with 0ad, bitcoin or dogecoin. dolphin-emu is probably too involved to configure to use it but you could test with strace to see if the lib is loaded ok. In VirtualBox, M5, KDE, 32-bit Package(s) under test: miniupnpc libminiupnpc12 0ad dolphin-emu bitcoin-qt install miniupnpc & libminiupnpc12 from updates_testing [root@localhost wilcal]# urpmi miniupnpc Package miniupnpc-1.9.20141128-1.1.mga5.i586 is already installed [root@localhost wilcal]# urpmi libminiupnpc12 Package libminiupnpc12-1.9.20141128-1.1.mga5.i586 is already installed [root@localhost wilcal]# urpmi 0ad Package 0ad-0.0.18-1.mga5.i586 is already installed [root@localhost wilcal]# urpmi dolphin-emu Package dolphin-emu-4.0.2-8.5406.2.1.mga5.tainted.i586 is already installed [root@localhost wilcal]# urpmi bitcoin-qt Package bitcoin-qt-0.9.3-1.mga5.i586 is already installed 0ad opened to a frozen full black screen. Only way out was: ctrl-alt-backspace dolphin-emu opened an error window: The desktop entry file file:///home/wilcal/Desktop/dolphin-emu.desktop has no Type=...entry. bitcoin-qt seemed to operate properly. I donno if this is enough to push this on? Or not? In VirtualBox, M5, KDE, 64-bit Package(s) under test: miniupnpc lib64miniupnpc12 0ad dolphin-emu bitcoin-qt install miniupnpc & lib64miniupnpc12 from updates_testing [root@localhost wilcal]# urpmi miniupnpc Package miniupnpc-1.9.20141128-1.1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi lib64miniupnpc12 Package lib64miniupnpc12-1.9.20141128-1.1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi 0ad Package 0ad-0.0.18-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi dolphin-emu Package dolphin-emu-4.0.2-8.5406.2.1.mga5.tainted.x86_64 is already installed [root@localhost wilcal]# urpmi bitcoin-qt Package bitcoin-qt-0.9.3-1.mga5.x86_64 is already installed 0ad opened to a frozen full pixeled screen mess. Only way out was: ctrl-alt-backspace dolphin-emu opened but "Dolphin could not find any GameCube/Wii ISOs or WADs" bitcoin-qt seemed to operate properly. I donno if this is enough to push this on? Or not? Is there a maintainer for these games? Maybe Rémi knows more about those games. CC:
(none) =>
rverschelde Note that bitcoin-qt is not a game :) For 0ad I wouldn't expect it to be able to start in a VM unless you changed it since last time you had issues starting an OpenGL application in Vbox. For dolphin-emu, as it's an emulator, you indeed need GameCube or Wii ISOs to be able to run game. Megaglest could also be used to test the update candidate, but it also requires OpenGL. I'll do some tests on real hw 64bit. Testing on Mageia 5 x86_64. Tested megaglest and 0ad, they work fine, including the multiplayer lobby (which is the part most likely to be impacted by an update to miniupnpc). dolphin-emu works fine too, but I did not try its networking features. Whiteboard:
advisory =>
advisory MGA5-64-OK Validating, please push to 5 core/updates. Keywords:
(none) =>
validated_update An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGASA-2015-0416.html Status:
NEW =>
RESOLVED |