Bug 29141

Summary: libjpeg new security issue CVE-2020-17541
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: David GEIGER <geiger.david68210>
Status: RESOLVED INVALID QA Contact: Sec team <security>
Severity: normal    
Priority: Normal    
Version: 7   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: libjpeg-2.1.0-1.mga9.src.rpm CVE:
Status comment:

Description David Walser 2021-06-16 19:12:08 CEST
SUSE has issued an advisory on July 11:
https://lists.suse.com/pipermail/sle-security-updates/2021-June/009002.html

Mageia 7 and Mageia 8 are also affected.
David Walser 2021-06-16 19:12:19 CEST

CC: (none) => geiger.david68210
Whiteboard: (none) => MGA8TOO, MGA7TOO

Comment 1 Lewis Smith 2021-06-17 21:29:46 CEST
Changing DavidG from CC to Assignee - lately the active maintainer.

Assignee: bugsquad => geiger.david68210
CC: geiger.david68210 => (none)

Comment 2 David Walser 2021-06-21 19:18:34 CEST
openSUSE has issued an advisory for this on June 17:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5QFMY5PC6YGRRPOTKEDLIS6VQ2KCVUDF/
Comment 3 David Walser 2021-06-27 22:38:37 CEST
This issue was fixed upstream in 2.0.4, so we're good.

Status: NEW => RESOLVED
Version: Cauldron => 7
Resolution: (none) => INVALID
Whiteboard: MGA8TOO, MGA7TOO => (none)