Bug 24182

Summary: php-pear-Archive_Tar new security issue CVE-2018-1000888
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Marc Krämer <mageia>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: major    
Priority: Normal CC: mageia, marja11
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: php-pear-Archive_Tar-1.4.3-2.mga7.src.rpm CVE:
Status comment:

Description David Walser 2019-01-14 20:34:41 CET
Ubuntu has issued an advisory today (January 14):
https://usn.ubuntu.com/3857-1/

The issue is fixed upstream in 1.4.4 (with a regression fix in 1.4.5).

Mageia 6 is also affected.
David Walser 2019-01-14 20:34:49 CET

Whiteboard: (none) => MGA6TOO

Comment 1 Marja Van Waes 2019-01-15 08:26:33 CET
Assigning to the PHP stack maintainers.

Assignee: bugsquad => php
CC: (none) => marja11

Comment 2 Marc Krämer 2019-01-15 10:49:19 CET
If I don't miss anything we don't have this package in mga6.

Updated cauldron.

CC: (none) => mageia

Marc Krämer 2019-01-15 10:49:27 CET

Assignee: php => mageia

Comment 3 David Walser 2019-01-15 13:24:07 CET
Ahh indeed.  Thanks.

Fixed in php-pear-Archive_Tar-1.4.5-1.mga7.

Status: NEW => RESOLVED
Whiteboard: MGA6TOO => (none)
Resolution: (none) => FIXED

Comment 4 Marc Krämer 2019-01-15 14:02:19 CET
you are doing a good job, I was just wondering if I was wrong :)