Bug 26523

Summary: openssl new security issue CVE-2020-1967
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Mageia Bug Squad <bugsquad>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: critical    
Priority: Normal CC: nicolas.salguero, rihoward1
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: openssl-1.1.1f-1.mga8.src.rpm CVE:
Status comment: Fixed upstream in 1.1.1g

Description David Walser 2020-04-21 22:19:26 CEST
OpenSSL has issued an advisory today (April 21):
https://www.openssl.org/news/secadv/20200421.txt

The issue is fixed upstream in 1.1.1g.

1.0.2 and 1.1.0 are not affect, thus neither is Mageia 7.
David Walser 2020-04-21 22:19:40 CEST

Status comment: (none) => Fixed upstream in 1.1.1g

Comment 1 r howard 2020-04-22 02:08:52 CEST
With regards to 1.0.2 and 1.1.0 are not affect, thus neither is Mageia 7. That may or may not be true as OpenSSL 1.0.2 and 1.1.0 are no longer supported by the OpenSSL project.
From https://www.openssl.org/policies/releasestrat.html :
Version 1.0.2 is no longer supported. Extended support for 1.0.2 to gain access to security fixes for that version is available.
Versions 1.1.0, 1.0.1, 1.0.0 and 0.9.8 are no longer supported.

CC: (none) => rihoward1

Comment 2 David Walser 2020-04-22 02:11:46 CEST
The advisory explicitly stated that older branches are not affected.
Comment 3 r howard 2020-04-22 02:37:58 CEST
David my apologies.  I was super busy and only read the first line of the advisory. I should of read more.

I guess I should ask the question in the email listif OpenSSL 1.1.1g should be back ported to Mageia 7
Comment 4 David Walser 2020-04-22 02:41:49 CEST
Ideally it would be (I filed Bug 24433 for that a long time ago), but it's not as simple as backporting the newer openssl itself, but we would also have to backport updates and/or patches for all of the packages using it, to be compatible with the API changes, and that hasn't even completely happened in Cauldron yet.
Comment 5 r howard 2020-04-22 02:48:56 CEST
Yes that sounds like a reasonable limitation due to shortage of packagers.
Comment 6 Nicolas Salguero 2020-04-22 15:55:23 CEST
Hi,

This is done: openssl-1.1.1g-1.mga8.

Best regards,

Nico.

CC: (none) => nicolas.salguero

Comment 7 David Walser 2020-04-22 16:00:59 CEST
Thanks!

Resolution: (none) => FIXED
Status: NEW => RESOLVED