Bug 27653

Summary: pulseaudio new security issue CVE-2020-16123
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: All Packagers <pkg-bugs>
Status: RESOLVED INVALID QA Contact: Sec team <security>
Severity: major    
Priority: Normal CC: geiger.david68210, jani.valimaa, ouaurelien
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA7TOO
Source RPM: pulseaudio-13.99.3-1.mga8.src.rpm CVE:
Status comment:

Description David Walser 2020-11-23 20:01:20 CET
Ubuntu has issued an advisory today (November 23):
https://ubuntu.com/security/notices/USN-4640-1

Mageia 7 is also affected.
David Walser 2020-11-23 20:01:26 CET

Whiteboard: (none) => MGA7TOO

Comment 1 Aurelien Oudelet 2020-11-23 20:12:06 CET
An Ubuntu-specific patch caused PulseAudio to incorrectly handle snap client connections.
Do we provide this?
http://svnweb.mageia.org/packages/cauldron/pulseaudio/current/SPECS/pulseaudio.spec?revision=1641577&view=markup

I am not an expert but I don't see this in SPEC file.

CC: (none) => ouaurelien

Comment 2 Aurelien Oudelet 2020-11-23 20:15:43 CET
Meanwhile, assigning to all packagers.
Cc'd recent commiter.

Assignee: bugsquad => pkg-bugs
CC: (none) => geiger.david68210, jani.valimaa

Comment 3 David Walser 2020-11-23 21:05:34 CET
Thanks, sorry for the noise.

Resolution: (none) => INVALID
Status: NEW => RESOLVED

Comment 4 Aurelien Oudelet 2020-11-23 21:16:21 CET
Meanwhile (again) PulseAudio 14.0 is released.
https://www.freedesktop.org/wiki/Software/PulseAudio/Notes/14.0/