Bug 29029

Summary: cimg new security issue CVE-2020-25693
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: David GEIGER <geiger.david68210>
Status: RESOLVED DUPLICATE QA Contact: Sec team <security>
Severity: major    
Priority: Normal CC: nicolas.salguero
Version: 7   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: cimg-2.5.7-1.1.mga7.src.rpm CVE:
Status comment: Fixed upstream in 2.9.3

David Walser 2021-05-29 23:04:50 CEST

CC: (none) => geiger.david68210, nicolas.salguero
Status comment: (none) => Fixed upstream in 2.9.3

Comment 1 Lewis Smith 2021-05-30 20:47:21 CEST
Cauldron is at 2.9.7; DavidG already did the commit for this CVE long ago.
Nov 24 2020 : new version: 2.9.3, fixes CVE-2020-25693 (mga#27651, bug 27651)
Has this already gone out? Yes.

In fact this bug looks like a duplicate of 27651. If you agree, David, please close it appropriately. In the circumstances, I hesitate in case I have it wrong.

Assignee: bugsquad => geiger.david68210
CC: geiger.david68210 => (none)

Comment 2 David Walser 2021-05-31 01:46:56 CEST
Yep.

*** This bug has been marked as a duplicate of bug 27651 ***

Resolution: (none) => DUPLICATE
Status: NEW => RESOLVED