Bug 19579

Summary: bubblewrap new security issue CVE-2016-8659
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Neal Gompa <ngompa13>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal    
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
See Also: https://bugzilla.redhat.com/show_bug.cgi?id=1384393
https://github.com/projectatomic/bubblewrap/issues/107
Whiteboard:
Source RPM: bubblewrap-0.1.2-mga6.src.rpm CVE: CVE-2016-8659
Status comment:

Description David Walser 2016-10-13 12:33:28 CEST
A CVE has been assigned for a security issue in bubblewrap:
http://www.openwall.com/lists/oss-security/2016/10/13/2

No fix is available yet.
Neal Gompa 2016-10-13 13:19:13 CEST

CVE: (none) => CVE-2016-8659
See Also: (none) => https://bugzilla.redhat.com/show_bug.cgi?id=1384393

Neal Gompa 2016-10-13 13:23:05 CEST

See Also: (none) => https://github.com/projectatomic/bubblewrap/issues/107

Comment 1 Neal Gompa 2016-10-14 18:18:28 CEST
A patch to mitigate the issue has been applied in bubblewrap-0.1.2-2.mga6.

See the following for details:

* https://github.com/projectatomic/bubblewrap/issues/107

* https://github.com/projectatomic/bubblewrap/pull/110

Status: NEW => RESOLVED
Resolution: (none) => FIXED