| Summary: | cairo new security issue CVE-2016-9082 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | brtians1, davidwhodgins, mageia, marja11, sysadmin-bugs |
| Version: | 5 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/705119/ | ||
| Whiteboard: | advisory MGA5-64-OK MGA5-32-OK | ||
| Source RPM: | cairo-1.14.6-3.mga6.src.rpm | CVE: | CVE-2016-9082 |
| Status comment: | |||
|
Description
David Walser
2016-10-27 14:12:53 CEST
David Walser
2016-10-27 14:13:33 CEST
Whiteboard:
(none) =>
MGA5TOO Assigning to the registered maintainer. CC:
(none) =>
marja11 Debian-LTS has issued an advisory for this on October 28: http://lwn.net/Alerts/705059/ URL:
(none) =>
http://lwn.net/Vulnerabilities/705119/
Nicolas Lécureuil
2017-04-27 13:35:42 CEST
CVE:
(none) =>
CVE-2016-9082
Nicolas Lécureuil
2017-04-27 13:54:05 CEST
Whiteboard:
MGA5TOO =>
(none) fixed in cauldron Patched package uploaded for Mageia 5. Advisory: ======================== Updated cairo packages fix security vulnerability: It was discovered that there was a possible DoS attack in Cairo. An SVG could generate invalid pointers from a _cairo_image_surface in write_png (CVE-2016-9082). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9082 https://lwn.net/Alerts/705059/ ======================== Updated packages in core/updates_testing: ======================== libcairo2-1.14.0-1.1.mga5 libcairo-devel-1.14.0-1.1.mga5 libcairo-static-devel-1.14.0-1.1.mga5 from cairo-1.14.0-1.1.mga5.src.rpm Assignee:
shlomif =>
qa-bugs $ uname -a Linux localhost.localdomain 4.4.74-desktop-1.mga5 #1 SMP Mon Jun 26 08:33:18 UTC 2017 i686 i686 i686 GNU/Linux I installed the library plus inkscape. Inkscape seems to be working as designed. $ uname -a Linux localhost.localdomain 4.4.74-desktop-1.mga5 #1 SMP Mon Jun 26 08:33:18 UTC 2017 i686 i686 i686 GNU/Linux I installed the library plus inkscape. Inkscape seems to be working as designed. CC:
(none) =>
brtians1 $ uname -a Linux localhost.localdomain 4.4.74-desktop-1.mga5 #1 SMP Mon Jun 26 08:33:18 UTC 2017 i686 i686 i686 GNU/Linux I installed the library plus inkscape. Inkscape seems to be working as designed. [dave@i5v ~]$ strace -f -ostrace.txt gpaint-2 /var/lib/mageia/kde4-profiles/Default/share/icons/oxygen/128x128/places/mgabutton.png
[dave@i5v ~]$ grep cairo.so strace.txt
5342 open("/lib/libcairo.so.2", O_RDONLY|O_CLOEXEC) = 3
[dave@x5v ~]$ strace -f -ostrace.txt gpaint-2 /var/lib/mageia/kde4-profiles/Default/share/icons/oxygen/128x128/places/mgabutton.png
[dave@x5v ~]$ grep cairo.so strace.txt
5246 open("/lib64/libcairo.so.2", O_RDONLY|O_CLOEXEC) = 3
Validating the update.Keywords:
(none) =>
validated_update An update for this issue has been pushed to the Mageia Updates repository. http://advisories.mageia.org/MGASA-2017-0205.html Resolution:
(none) =>
FIXED |