| Summary: | autotrace new security issues CVE-2017-915[1-9], CVE-2017-91[6-9][0-9], CVE-2017-9200 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | Shlomi Fish <shlomif> |
| Status: | RESOLVED OLD | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | marja11 |
| Version: | 5 | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | autotrace-0.31.1-46.1.mga5.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2017-05-23 13:08:29 CEST
David Walser
2017-05-23 13:08:36 CEST
Whiteboard:
(none) =>
MGA5TOO Assigning to the registered maintainer. CC:
(none) =>
marja11 AutoTrace is unmaintained since 2005, and there is no apparent fix for those CVEs yet (at least at Debian and Fedora). Fedora decided it would be a WONTFIX for them: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-9151 I would suggest dropping it for Mageia 6 provided it has no reverse dependencies that can't be made to work against more recent bitmap converters. Status comment:
(none) =>
Candidate for dropping if no reverse deps Fixed in Mageia 6 by dropping autotrace. For Mageia 5, I suggest to close as WONTFIX as Fedora did, as I don't expect those 50 security issues will ever be patched in such unmaintained software. Whiteboard:
MGA5TOO =>
(none)
Rémi Verschelde
2017-06-30 23:51:57 CEST
Status comment:
Candidate for dropping if no reverse deps =>
(none) This is dead software. Status:
NEW =>
RESOLVED |