| Summary: | tigervnc new security issues CVE-2017-5581, CVE-2017-739[2-6], and CVE-2016-10207 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | All Packagers <pkg-bugs> |
| Status: | RESOLVED OLD | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | marja11 |
| Version: | 5 | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | https://lwn.net/Vulnerabilities/712666/ | ||
| Whiteboard: | |||
| Source RPM: | tigervnc-1.3.1-6.1.mga5.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2017-01-25 12:04:33 CET
Assigning to all packagers collectively, since there is no registered maintainer for this package CC:
(none) =>
marja11
David Walser
2017-01-27 00:20:49 CET
URL:
(none) =>
https://lwn.net/Vulnerabilities/712666/ openSUSE has issued an advisory for this on January 26: http://lists.opensuse.org/opensuse-updates/2017-01/msg00146.html They ported the patch as far back as 1.5.0, which may or may not help. CVE-2017-10207 assigned for another issues fixed upstream: http://openwall.com/lists/oss-security/2017/02/05/2 This one has only been fixed upstream in master so far, not in 1.7-branch. Summary:
tigervnc new security issue CVE-2017-5581 =>
tigervnc new security issues CVE-2017-5581 and CVE-2017-10207 (In reply to David Walser from comment #3) > CVE-2017-10207 assigned for another issues fixed upstream: > http://openwall.com/lists/oss-security/2017/02/05/2 > > This one has only been fixed upstream in master so far, not in 1.7-branch. openSUSE has issued an advisory for this on February 11: http://lists.opensuse.org/opensuse-updates/2017-02/msg00053.html LWN reference: https://lwn.net/Vulnerabilities/714431/ RedHat has issued an advisory for this on March 21: https://rhn.redhat.com/errata/RHSA-2017-0630.html Fedora has issued an advisory on April 7: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/AWXMLXNVUGAYE5VUZEHB7MRIQJNP6VAI/ It fixes more new security issues. Summary:
tigervnc new security issues CVE-2017-5581 and CVE-2017-10207 =>
tigervnc new security issues CVE-2017-5581, CVE-2017-739[2-6], and CVE-2017-10207 (In reply to David Walser from comment #3) > CVE-2017-10207 assigned for another issues fixed upstream: > http://openwall.com/lists/oss-security/2017/02/05/2 > > This one has only been fixed upstream in master so far, not in 1.7-branch. Oops, CVE-2016-10207. Summary:
tigervnc new security issues CVE-2017-5581, CVE-2017-739[2-6], and CVE-2017-10207 =>
tigervnc new security issues CVE-2017-5581, CVE-2017-739[2-6], and CVE-2016-10207 Patching this appears to be impossible. It looks like it actually *could* be upgraded to 1.8.0, but that would require upgrading fltk to 1.3.3 or 1.3.4, which would require rebuilding several packages. So, that won't be happening. Sorry. Resolution:
(none) =>
OLD |