| Summary: | dcraw new security issues CVE-2017-13735, CVE-2017-14265, CVE-2017-14348 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | All Packagers <pkg-bugs> |
| Status: | RESOLVED DUPLICATE | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | mageia, marja11, nicolas.salguero, qa-bugs, security |
| Version: | Cauldron | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8TOO, MGA7TOO | ||
| Source RPM: | dcraw-9.27.0-1.mga6.src.rpm | CVE: | |
| Status comment: | Patches available from upstream | ||
| Bug Depends on: | 21716, 24107 | ||
| Bug Blocks: | |||
|
Description
David Walser
2017-09-22 17:14:00 CEST
David Walser
2017-09-22 17:14:14 CEST
Whiteboard:
(none) =>
MGA6TOO, MGA5TOO Assigning to the registered maintainer of dcraw Assignee:
bugsquad =>
shlomif
David Walser
2017-09-25 16:53:48 CEST
Summary:
dcraw new security issues CVE-2017-13735 and CVE-2017-14265 =>
dcraw new security issues CVE-2017-13735, CVE-2017-14265, CVE-2017-14348 Nobody has patches for this yet, so we won't be able to fix this for Mageia 5. Whiteboard:
MGA6TOO, MGA5TOO =>
MGA6TOO
David Walser
2018-02-02 18:18:37 CET
Status comment:
(none) =>
Not fixed upstream as of end of 2017
David Walser
2018-06-29 19:51:34 CEST
See Also:
(none) =>
https://bugs.mageia.org/show_bug.cgi?id=23252
David Walser
2019-01-02 15:12:32 CET
See Also:
https://bugs.mageia.org/show_bug.cgi?id=23252 =>
(none)
David Walser
2019-01-02 15:13:02 CET
See Also:
(none) =>
https://bugs.mageia.org/show_bug.cgi?id=24107
David Walser
2019-06-23 19:25:02 CEST
Whiteboard:
MGA6TOO =>
MGA7TOO, MGA6TOO Re-assigning globally due to change to no specific maintainer. Whiteboard:
MGA7TOO, MGA6TOO =>
MGA7TOO
David Walser
2020-01-14 18:10:47 CET
See Also:
https://bugs.mageia.org/show_bug.cgi?id=24107 =>
(none) Nicolas Salguero added patches for CVE-2017-13735 and CVE-2017-14608 in dcraw-9.28.0-4.mga8 in Cauldron.
David Walser
2020-12-28 17:09:31 CET
Whiteboard:
MGA7TOO =>
MGA8TOO, MGA7TOO just for the record: https://security-tracker.debian.org/tracker/CVE-2017-13735 with fix: https://github.com/LibRaw/LibRaw/files/1276421/radc_divbyzero.txt https://security-tracker.debian.org/tracker/CVE-2017-14265 with fix: https://github.com/LibRaw/LibRaw/commit/82616eff4c7f7437e96bdeeed238c3ef3dc12d60 https://security-tracker.debian.org/tracker/CVE-2017-14348 with fix: https://github.com/LibRaw/LibRaw/commit/8303e74b0567806dd5f16fc39aab70fe928de1a2 CC:
(none) =>
mageia
David Walser
2020-12-28 22:10:22 CET
Status comment:
Not fixed upstream as of end of 2017 =>
Patches available from upstream rawtherapee pushed in mga7 to fix CVE-2017-13735
src:
rawtherapee-5.6-1.1.mga7Status comment:
Patches available from upstream =>
Not fixed upstream as of end of 2017
Nicolas Lécureuil
2020-12-28 22:38:42 CET
Status comment:
Not fixed upstream as of end of 2017 =>
Patches available from upstream (In reply to Nicolas Lécureuil from comment #7) > rawtherapee pushed in mga7 to fix CVE-2017-13735 > > src: > rawtherapee-5.6-1.1.mga7 Thanks, this update is in Bug 27963. Removing CVE-2017-14348 due to this: https://bugzilla.redhat.com/show_bug.cgi?id=1492123#c9 Otherwise it looks like we fixed all fixable issues in Bug 26406. *** This bug has been marked as a duplicate of bug 26406 *** Resolution:
(none) =>
DUPLICATE |