| Summary: | mbedtls new security issues fixed upstream in 2.16.5 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | andrewsfarm, sysadmin-bugs, tarazed25, tmb |
| Version: | 7 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA7-64-OK | ||
| Source RPM: | mbedtls-2.16.4-1.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2020-02-26 02:38:13 CET
David Walser
2020-02-26 02:38:27 CET
Status comment:
(none) =>
Fixed upstream in 2.16.5
Rémi Verschelde
2020-02-26 08:40:54 CET
Status:
NEW =>
ASSIGNED Fixed in Cauldron with mbedtls-2.16.5-1.mga8. Pushed mbedtls-2.16.5-1.mga7 to Mageia 7 core/updates_testing. RPMs in core/updates_testing: ============================= lib64mbedcrypto3-2.16.5-1.mga7 lib64mbedtls12-2.16.5-1.mga7 lib64mbedtls-devel-2.16.5-1.mga7 lib64mbedx509_0-2.16.5-1.mga7 mbedtls-2.16.5-1.mga7 SRPM in core/updates_testing: ============================= mbedtls-2.16.5-1.mga7 Advisory pending. Whiteboard:
MGA7TOO =>
(none)
David Walser
2020-03-05 17:59:13 CET
Status comment:
Fixed upstream in 2.16.5 =>
(none) mga7, x86_64 Updated the packages, all of which were already installed at previous version. Referred to previous test in https://bugs.mageia.org/show_bug.cgi?id=25952. godot-3.1.1-1.mga7 already installed. Launched godot and accessed "Templates", browsed a bit, then selected "2D Finite State Machine Demo", looked at the description, then downloaded the demo. Entered the editor and selected AssetLib and browsed a few more projects, selected NotesTab, downloaded and installed that. Hopefully that exercised mbedtls. Forgot to run a trace. The user's godot directory looks like this: $ tree godot godot ├── addons │ └── notes_tab │ ├── LICENSE │ ├── notes_tab.gd │ ├── notes_tab.tscn ...... ├── project.godot └── state_machine ├── state.gd └── state_machine.gd 14 directories, 43 files Giving this an OK for 64-bits. CC:
(none) =>
tarazed25
Thomas Backlund
2020-03-06 23:19:31 CET
CC:
(none) =>
tmb Validating. Keywords:
(none) =>
validated_update An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2020-0130.html Resolution:
(none) =>
FIXED Thanks for writing the advisory Thomas :) Fedora has issued an advisory for this on March 12: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/2U5SD5ORL6H6YYMFTMQNOIGNNXVYVCAM/ |