| Summary: | pdfbox new security issues CVE-2021-27807 and CVE-2021-27906 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, mageia, ouaurelien, sysadmin-bugs |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | pdfbox-2.0.21-2.mga8.src.rpm | CVE: | CVE-2021-27807, CVE-2021-27906 |
| Status comment: | |||
| Bug Depends on: | |||
| Bug Blocks: | 28708 | ||
|
Description
David Walser
2021-03-30 23:25:29 CEST
David Walser
2021-03-30 23:25:46 CEST
Version:
Cauldron =>
8
David Walser
2021-03-30 23:27:13 CEST
Blocks:
(none) =>
23251
Nicolas Lécureuil
2021-04-03 00:26:21 CEST
Blocks:
(none) =>
28708 fixed in mga8:
src:
- pdfbox-2.0.23-1.mga8
bug cloned in 28708 for mga7Whiteboard:
MGA7TOO =>
(none)
Nicolas Lécureuil
2021-04-03 00:28:13 CEST
Assignee:
java =>
qa-bugs
David Walser
2021-04-03 00:30:52 CEST
Blocks:
(none) =>
28708 Advisory: ======================== Updated pdfbox packages fix security vulnerabilities: A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox Apache PDFBox version 2.0.22 and prior 2.0.x versions (CVE-2021-27807). A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox Apache PDFBox version 2.0.22 and prior 2.0.x versions (CVE-2021-27906). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27807 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27906 https://www.openwall.com/lists/oss-security/2021/03/19/9 https://www.openwall.com/lists/oss-security/2021/03/19/10 ======================== Updated packages in core/updates_testing: ======================== pdfbox-2.0.23-1.mga8 xmpbox-2.0.23-1.mga8 pdfbox-tools-2.0.23-1.mga8 pdfbox-parent-2.0.23-1.mga8 pdfbox-reactor-2.0.23-1.mga8 pdfbox-javadoc-2.0.23-1.mga8 pdfbox-debugger-2.0.23-1.mga8 fontbox-2.0.23-1.mga8 preflight-2.0.23-1.mga8 from pdfbox-2.0.23-1.mga8.src.rpm Installed all packages, including numerous dependencies, in a vbox mga8 Plasma guest. Referenced Bug 18558 for testing suggestions, where I read that QA had been advised to OK this on a clean install and update over the previous versions. Updated using qarepo, with no issues, so it looks OK here. Validating. Advisory in Comment 2. Keywords:
(none) =>
validated_update
Aurelien Oudelet
2021-04-12 16:27:32 CEST
CC:
(none) =>
ouaurelien An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0184.html Status:
NEW =>
RESOLVED Fedora has issued an advisory for this on March 26: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6PT72QOFDXLJ7PLTN66EMG5EHPTE7TFZ/ |