Bug 27735

Summary: checkstyle new security issue CVE-2019-10782
Product: Mageia Reporter: Zombie Ryushu <zombie_ryushu>
Component: SecurityAssignee: Nicolas Lécureuil <mageia>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: ouaurelien
Version: 7   
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-10782
Whiteboard:
Source RPM: checkstyle-8.0-3.mga7.src.rpm CVE: CVE-2019-10782
Status comment: Patch checked into SVN

Description Zombie Ryushu 2020-12-04 10:37:38 CET
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
Zombie Ryushu 2020-12-04 10:38:26 CET

CVE: (none) => CVE-2019-10782

Comment 1 David Walser 2020-12-04 13:34:29 CET
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10782

Package dropped in Cauldron.

Source RPM: checkstyle => checkstyle-8.0-3.mga7.src.rpm
Summary: checkstyle security vulnerability CVE-2019-10782 => checkstyle new security issue CVE-2019-10782

Comment 2 Aurelien Oudelet 2020-12-07 10:39:12 CET
Hi, thanks for reporting this.
Assigned to the package maintainer.

(Please set the status to 'assigned' if you are working on it)

CC: (none) => ouaurelien
Assignee: bugsquad => mageia

Comment 3 David Walser 2020-12-28 19:10:39 CET
Debian-LTS has issued an advisory for this on February 10:
https://www.debian.org/lts/security/2020/dla-2099

This was actually filed as Bug 26219 before, but wrongly closed.
David Walser 2020-12-28 19:10:58 CET

Status comment: (none) => Patch available from Debian

Comment 4 David Walser 2021-06-28 22:31:50 CEST
Patched checked into Mageia 7.  This is Java stuff that isn't really used by anything, so I don't think it's worth pushing an update, but feel free to push to the build system if you disagree.

Status comment: Patch available from Debian => Patch checked into SVN

Comment 5 David Walser 2021-07-01 18:25:18 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Resolution: (none) => OLD
Status: NEW => RESOLVED