Bug 22987

Summary: opencv new security issues CVE-2017-17760, CVE-2017-18009, CVE-2017-1000450, and more
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Shlomi Fish <shlomif>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: major    
Priority: Normal CC: marja11, mhrambo3501
Version: 6   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: opencv-2.4.12.3-5.mga6.src.rpm CVE:
Status comment: Patches available from Fedora and openSUSE

Description David Walser 2018-05-03 18:57:41 CEST
Fedora has issued an advisory today (May 3):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/VR5DCLWTSQMPCTUPXE4GMJSMGZJ7IE53/

CVE-2017-1000450 certainly affects Mageia 5 and Mageia 6, but it's not clear if CVE-2017-17760 affects either one.  The issues were fixed in 3.4.0, so Cauldron is not affected.
Comment 1 Marja Van Waes 2018-05-03 21:07:33 CEST
Assigning to the registered maintainer.

CC: (none) => marja11
Assignee: bugsquad => shlomif

David Walser 2018-05-04 08:25:09 CEST

Status comment: (none) => Patches available from Fedora

Comment 2 David Walser 2018-06-07 23:40:29 CEST
openSUSE advisories from May 12, 23, and 28, fix these issues and several more:
https://lists.opensuse.org/opensuse-updates/2018-05/msg00038.html
https://lists.opensuse.org/opensuse-updates/2018-05/msg00089.html
https://lists.opensuse.org/opensuse-updates/2018-05/msg00128.html

CVE-2016-1516 CVE-2016-1517
CVE-2017-12597 CVE-2017-12598
CVE-2017-12599 CVE-2017-12600 CVE-2017-12601
CVE-2017-12602 CVE-2017-12603 CVE-2017-12604
CVE-2017-12605 CVE-2017-12606 CVE-2017-12862
CVE-2017-12863 CVE-2017-12864 CVE-2017-14136
CVE-2017-18009 CVE-2018-5268 CVE-2018-5269

are the new issues.
Comment 3 David Walser 2018-06-15 18:51:22 CEST
openSUSE has issued an advisory today (June 15) for CVE-2017-18009:
https://lists.opensuse.org/opensuse-updates/2018-06/msg00086.html

Summary: opencv new security issues CVE-2017-17760 and CVE-2017-1000450 => opencv new security issues CVE-2017-17760, CVE-2017-18009, CVE-2017-1000450, and more
Status comment: Patches available from Fedora => Patches available from Fedora and openSUSE

Comment 4 Mike Rambo 2019-11-06 13:27:30 CET
Mageia 6 is EOL.

Resolution: (none) => OLD
CC: (none) => mrambo
Status: NEW => RESOLVED