| Summary: | htmldoc new security issue CVE-2019-19630 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | andrewsfarm, geiger.david68210, herman.viaene, sysadmin-bugs, tmb |
| Version: | 7 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA7-64-OK | ||
| Source RPM: | htmldoc-1.9.3-2.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2019-12-14 19:03:58 CET
David Walser
2019-12-14 19:04:06 CET
Whiteboard:
(none) =>
MGA7TOO Assigning to Shlomi as both the registered maintainer and most recent committer. Assignee:
bugsquad =>
shlomif 1.9.8 is not yet released. CC:
(none) =>
geiger.david68210 The commit that fixes the issue is: https://github.com/michaelrsweet/htmldoc/commit/8a129c520e90fc967351f3e165f967128a88f09c Fixed both Cauldron and mga7! Advisory: ======================== Updated htmldoc packages fix security vulnerability: In HTMLDOC, there was a one-byte underflow in htmldoc/ps-pdf.cxx caused by a floating point math difference between GCC and Clang (CVE-2019-19630). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19630 https://www.debian.org/lts/security/2019/dla-2026 ======================== Updated packages in core/updates_testing: ======================== htmldoc-1.9.3-2.1.mga7 htmldoc-nogui-1.9.3-2.1.mga7 from htmldoc-1.9.3-2.1.mga7.src.rpm Version:
Cauldron =>
7 MGA7-64 Plasma on Lenovo B50 No installation issues. First tried command htmldoc, which is a gui an selected an html file which I made of an odt file (used in my own website) and convert that one to pdf. It throws an error saying "Did you not forget to apply webpage format". Note: this is a Dutch installation, but the whole thing seems to be English only. I could not find such setting in the gui, so I settled for the CLI: $ htmldoc-nogui -t pdf --webpage -f dond.pdf donderdag.html PAGES: 5 BYTES: 218271 The resulting pdf file is OK, so good enough for me. Whiteboard:
(none) =>
MGA7-64-OK Validating. Advisory in Comment 5. Keywords:
(none) =>
validated_update
Thomas Backlund
2019-12-19 13:46:36 CET
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2019-0403.html Resolution:
(none) =>
FIXED |