Bug 21940

Summary: libraw new security issue CVE-2017-14608
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Nicolas Salguero <nicolas.salguero>
Status: RESOLVED DUPLICATE QA Contact: Sec team <security>
Severity: normal    
Priority: Normal    
Version: 5   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: libraw-0.16.2-1.4.mga5.src.rpm CVE:
Status comment:

Description David Walser 2017-10-26 18:15:45 CEST
openSUSE has issued an advisory on October 25:
https://lists.opensuse.org/opensuse-updates/2017-10/msg00089.html

We fixed this for Mageia 6 in Bug 21716, but probably didn't backport it for 5.
Comment 1 Nicolas Salguero 2017-11-02 14:45:34 CET
Hi,

After checking, it appears that the patch for CVE-2017-14608 is contained into the patch for CVE-2017-14348 in our Mageia 5 package so the problem is already solved.

Best regards,

Nico.

Resolution: (none) => FIXED
Status: NEW => RESOLVED

Comment 2 David Walser 2017-11-03 13:04:25 CET
Thanks Nicolas!

*** This bug has been marked as a duplicate of bug 21716 ***

Resolution: FIXED => DUPLICATE