Bug 27723

Summary: ampache new security issues CVE-2019-1238[56]
Product: Mageia Reporter: Zombie Ryushu <zombie_ryushu>
Component: SecurityAssignee: All Packagers <pkg-bugs>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: ouaurelien
Version: 7   
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: https://bugzilla.rosalinux.ru/show_bug.cgi?id=10712
Whiteboard:
Source RPM: ampache-3.8.8-3.1.mga7.src.rpm CVE: CVE-2019-12385, CVE-2019-12386
Status comment: Patches available from Debian and Ubuntu

Description Zombie Ryushu 2020-12-04 00:28:35 CET
CVE-2019-12385 2019-08-22T19:15Z 2019-11-11T16:15Z 	
ampache
ampache
	(-∞, 3.9.1]
CVE-2019-12386 2019-08-22T19:15Z 2019-11-11T16:15Z 	
ampache
ampache
	(-∞, 3.9.1]
Zombie Ryushu 2020-12-04 00:32:50 CET

QA Contact: (none) => security
Status comment: (none) => CVE-2019-12386
Component: RPM Packages => Security
CVE: (none) => CVE-2019-12386

Comment 1 David Walser 2020-12-04 00:56:02 CET
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12385
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12386

Status comment: CVE-2019-12386 => (none)
CVE: CVE-2019-12386 => CVE-2019-12385, CVE-2019-12386
Summary: [Update Request] ampache CVE-2019-12386 => ampache new security issues CVE-2019-1238[56]

Comment 2 Aurelien Oudelet 2020-12-07 10:48:38 CET
Hi, thanks for reporting this.
Assigned to the package maintainer.

(Please set the status to 'assigned' if you are working on it)

Assignee: bugsquad => shlomif
CC: (none) => ouaurelien
Source RPM: ampache => ampache-3.8.8-3.1.mga7.src.rpm

David Walser 2020-12-27 23:48:05 CET

Assignee: shlomif => pkg-bugs
CC: (none) => luigiwalser

David Walser 2020-12-27 23:48:47 CET

CC: luigiwalser => (none)

Comment 3 David Walser 2020-12-28 19:07:25 CET
Debian-LTS has issued an advisory for this on November 11, 2019:
https://www.debian.org/lts/security/2019/dla-1988

Status comment: (none) => Patches available from Debian

Comment 4 David Walser 2021-01-15 21:29:17 CET
Ubuntu has issued an advisory for this on January 14:
https://ubuntu.com/security/notices/USN-4693-1

Status comment: Patches available from Debian => Patches available from Debian and Ubuntu

Comment 5 David Walser 2021-07-01 18:25:07 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Status: NEW => RESOLVED
Resolution: (none) => OLD