| Summary: | pdfbox new security issues CVE-2021-3181[12] | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, herman.viaene, mageia, ouaurelien, sysadmin-bugs |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | pdfbox-2.0.23-1.mga9.src.rpm | CVE: | CVE-2021-3181[12] |
| Status comment: | |||
| Bug Depends on: | |||
| Bug Blocks: | 28708 | ||
|
Description
David Walser
2021-06-13 23:43:37 CEST
David Walser
2021-06-13 23:44:13 CEST
Whiteboard:
(none) =>
MGA8TOO, MGA7TOO Fedora has issued an advisory for this today (June 24): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MDJKJQOMVFDFIDS27OQJXNOYHV2O273D/ Removing Mageia 7 from whiteboard due to EOL: https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/ Whiteboard:
MGA8TOO, MGA7TOO =>
MGA8TOO new version pushed in mga8/9
src:
- pdfbox-2.0.24-1.mga8Assignee:
java =>
qa-bugs pdfbox-2.0.24-1.mga8 pdfbox-debugger-2.0.24-1.mga8 fontbox-2.0.24-1.mga8 preflight-2.0.24-1.mga8 xmpbox-2.0.24-1.mga8 pdfbox-tools-2.0.24-1.mga8 pdfbox-parent-2.0.24-1.mga8 pdfbox-reactor-2.0.24-1.mga8 pdfbox-javadoc-2.0.24-1.mga8 from pdfbox-2.0.24-1.mga8.src.rpm Version:
Cauldron =>
8 Advisory: ======================== In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions (CVE-2021-31811). In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions (CVE-2021-31812). References: - https://bugs.mageia.org/show_bug.cgi?id=29125 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31811 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31812 - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MDJKJQOMVFDFIDS27OQJXNOYHV2O273D/ ======================== Updated packages in core/updates_testing: ======================== pdfbox-2.0.24-1.mga8 pdfbox-debugger-2.0.24-1.mga8 fontbox-2.0.24-1.mga8 preflight-2.0.24-1.mga8 xmpbox-2.0.24-1.mga8 pdfbox-tools-2.0.24-1.mga8 pdfbox-parent-2.0.24-1.mga8 pdfbox-reactor-2.0.24-1.mga8 pdfbox-javadoc-2.0.24-1.mga8 from pdfbox-2.0.24-1.mga8.src.rpm CC:
(none) =>
ouaurelien MGA8-64 Plasma on Lenovo B50 No installation issues. Ref bug 28682 where our boss recommends OK on clean install. I won't contradict him. Whiteboard:
(none) =>
MGA8-64-OK Good to know there's no dissension in the ranks. Validating. Advisory in Comment 5. Keywords:
(none) =>
validated_update
Aurelien Oudelet
2021-07-27 20:47:42 CEST
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0378.html Status:
NEW =>
RESOLVED |