| Summary: | pdfbox new security issues CVE-2018-8036, CVE-2018-11797, and CVE-2019-0228 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | Java Stack Maintainers <java> |
| Status: | RESOLVED OLD | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | geiger.david68210, zombie_ryushu |
| Version: | 7 | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | pdfbox-2.0.9-2.mga7.src.rpm | CVE: | CVE-2019-0228 |
| Status comment: | Fixed upstream in 2.0.16 | ||
| Bug Depends on: | 28708 | ||
| Bug Blocks: | |||
|
Description
David Walser
2018-06-29 15:16:12 CEST
David Walser
2018-06-29 15:16:26 CEST
Whiteboard:
(none) =>
MGA6TOO Updated advisory with references: http://openwall.com/lists/oss-security/2018/06/29/2 openSUSE has issued an advisory for this today (September 7): https://lists.opensuse.org/opensuse-updates/2018-09/msg00028.html Apache has issued an advisory today (October 5): https://www.openwall.com/lists/oss-security/2018/10/05/4 The issue is fixed upstream in 1.8.16 and 2.0.12. Summary:
pdfbox new security issue CVE-2018-8036 =>
pdfbox new security issues CVE-2018-8036 and CVE-2018-11797 openSUSE has issued an advisory for this today (October 24): https://lists.opensuse.org/opensuse-updates/2018-10/msg00157.html
David Walser
2019-06-23 19:31:08 CEST
Whiteboard:
MGA6TOO =>
MGA7TOO, MGA6TOO Fedora has issued an advisory for this on September 9: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/POPOGHJ5CVMUVCRQU7APBAN5IVZGZFDX/ It adds one new CVE, fixed upstream in 2.0.16. Again this was fixed in Cauldron with the CVEs in the commit message, but no bug for the new CVE. Whiteboard:
MGA7TOO, MGA6TOO =>
(none)
Zombie Ryushu
2020-12-23 08:14:33 CET
CVE:
(none) =>
CVE-2019-0228
David Walser
2021-03-30 23:27:13 CEST
Depends on:
(none) =>
28682
Nicolas Lécureuil
2021-04-03 00:26:21 CEST
Depends on:
(none) =>
28708
Nicolas Lécureuil
2021-04-03 00:27:57 CEST
Depends on:
28682 =>
(none) https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/ Resolution:
(none) =>
OLD |