| Summary: | python-psutil new security issue CVE-2019-18874 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | andrewsfarm, geiger.david68210, herman.viaene, sysadmin-bugs, tmb |
| Version: | 7 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA7-64-OK | ||
| Source RPM: | python-psutil-5.6.1-1.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2019-11-30 16:29:54 CET
David Walser
2019-11-30 16:30:04 CET
Whiteboard:
(none) =>
MGA7TOO Advisory: ======================== Updated python-psutil packages fix security vulnerability: Riccardo Schirone discovered that psutil incorrectly handled certain reference counting operations. An attacker could use this issue to cause psutil to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2019-18874). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18874 https://usn.ubuntu.com/4204-1/ ======================== Updated packages in core/updates_testing: ======================== python2-psutil-5.6.7-1.mga7 python3-psutil-5.6.7-1.mga7 from python-psutil-5.6.7-1.mga7.src.rpm Whiteboard:
MGA7TOO =>
(none) MGA7-64 Plasma on Lenovo B50 No installation issues. Used urpmq to find packages to test, picked terminator to test python2-psutil and glances for python3-psutil. Used strace to check the usage, both programs seemed to perform well, and the trace shows references to the packages under test. OK for me. Whiteboard:
(none) =>
MGA7-64-OK Validating. Advisory in Comment 2. Keywords:
(none) =>
validated_update
Thomas Backlund
2019-12-06 13:45:48 CET
CC:
(none) =>
tmb An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2019-0370.html Resolution:
(none) =>
FIXED |