Bug 24512

Summary: libcomps new security issue CVE-2019-3817
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Neal Gompa <ngompa13>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: major    
Priority: Normal    
Version: 6   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: libcomps-0.1.9-1.mga7.src.rpm CVE:
Status comment:

Description David Walser 2019-03-13 20:07:12 CET
openSUSE has issued an advisory on March 11:
https://lists.opensuse.org/opensuse-updates/2019-03/msg00054.html

Mageia 6 is also affected.
David Walser 2019-03-13 20:07:17 CET

Whiteboard: (none) => MGA6TOO

David Walser 2019-06-23 19:19:57 CEST

Whiteboard: MGA6TOO => MGA7TOO, MGA6TOO

Comment 1 David Walser 2019-11-12 18:11:13 CET
RedHat has issued an advisory for this on November 5:
https://access.redhat.com/errata/RHSA-2019:3583

The issue is fixed upstream in 0.1.10.

We shipped Mageia 7 with 0.1.11, and Mageia 6 is EOL.

Whiteboard: MGA7TOO, MGA6TOO => (none)
Status: NEW => RESOLVED
Resolution: (none) => OLD
Version: Cauldron => 6