| Summary: | libexif new security issues CVE-2020-0181 and CVE-2020-0182 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | All Packagers <pkg-bugs> |
| Status: | RESOLVED DUPLICATE | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | mageia, nicolas.salguero |
| Version: | Cauldron | Keywords: | Triaged |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA7TOO | ||
| Source RPM: | libexif-0.6.22-2.mga8.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2020-11-05 00:57:39 CET
David Walser
2020-11-05 00:57:46 CET
Whiteboard:
(none) =>
MGA7TOO Hi, thanks for reporting this bug. Assigned to all packagers, added recent commiters. (Please set the status to 'assigned' if you are working on it) Keywords:
(none) =>
Triaged Hi, According to RedHat and Debian the fix for CVE-2019-9278 and CVE-2020-0198 also fixed CVE-2020-0181. Looking at the source code of version 0.6.22, I found that the fix for CVE-2020-0182 is already present in the code. Best regards, Nico. Agreed based on this: https://git.centos.org/rpms/libexif/c/00b59c454861ef19aa3dfd26c6a7d0429fae37f9?branch=c8 *** This bug has been marked as a duplicate of bug 26814 *** Resolution:
(none) =>
DUPLICATE |