| Summary: | rpm crash parsing corrupted RPM files | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | RPM Packages | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, davidwhodgins, herman.viaene, sysadmin-bugs, thierry.vignaud |
| Version: | 5 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/665705/ | ||
| Whiteboard: | MGA5-32-OK MGA5-64-OK advisory | ||
| Source RPM: | rpm-4.12.0.1-20.3.mga5.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2015-12-01 21:21:38 CET
Note that for mga6, it'll be easier to sync patches with FC. I could do the same work on the mga5 branch if really needed. CC:
(none) =>
thierry.vignaud In cauldron, we apply first FC patches with the same number as in FC (making it easier to compare spec files between FC & mga with diff -uwBbd), then ours. From http://pkgs.fedoraproject.org/cgit/rpm.git/log/?h=f22, we could get one more fix: - Add query options for weak dependencies to the man page But it's not that important It's untested as yet, and just a man page fix, so go ahead if you like Thierry. Yeah, I saw that weakdeps man patch, and there was one other, a python3 something-or-other. I did use the same patch number as Fedora for the patch that I added. I thought about adding the two intermediate patches, but they didn't look important. Feel free to add them though if you would like. We already have the py3 fix (under another form) MGA5-32 on Acer D620 Xfce No installation issues. After installing operations seem normal. CC:
(none) =>
herman.viaene On my way to check out the fix for Bug 17267, concerning MageiaSync, Mageia Update insisted I test the 64-bit versions of these packages on my KDE system first. Fortunately for all concerned, they appear to be working. Adding a 64 OK to the whiteboard. Whiteboard:
MGA5-32-OK =>
MGA5-32-OK MGA5-64-OK Confirmed also seems OK on my 32-bit Intel system.
Dave Hodgins
2015-12-05 04:27:56 CET
Whiteboard:
MGA5-32-OK MGA5-64-OK =>
MGA5-32-OK MGA5-64-OK advisory An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGAA-2015-0199.html Status:
NEW =>
RESOLVED |