Bug 29199

Summary: dbus new security issue CVE-2020-35512
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: All Packagers <pkg-bugs>
Status: RESOLVED INVALID QA Contact: Sec team <security>
Severity: major    
Priority: Normal CC: nicolas.salguero, ouaurelien
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: dbus-1.13.18-3.mga8.src.rpm CVE:
Status comment:

Description David Walser 2021-07-01 14:41:45 CEST
SUSE has issued an advisory on June 30:
https://lists.suse.com/pipermail/sle-security-updates/2021-June/009108.html

Mageia 8 is also affected.
Comment 1 Lewis Smith 2021-07-01 20:45:52 CEST
No evident maintainer for dbus, so have to assign this bug globally.

Assignee: bugsquad => pkg-bugs

Comment 2 Nicolas Salguero 2021-07-02 11:49:04 CEST
Hi,

In fact, the bug is fixed in version 1.13.18.

Best regards,

Nico.

CC: (none) => nicolas.salguero

Comment 3 Aurelien Oudelet 2021-07-02 11:57:52 CEST
Yeah.
Closing.

Also, strange that we use 1.13.x which is development branch... ;)

CC: (none) => ouaurelien
Status: NEW => RESOLVED
Resolution: (none) => INVALID

Comment 4 David Walser 2021-07-12 17:40:52 CEST
openSUSE has issued an advisory for this today (July 12):
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YPWMH7OQGRFBQ2ZFL5Z3HCT443A45EIB/

Status comment: (none) => Patch available from openSUSE

David Walser 2021-07-12 17:41:08 CEST

Status comment: Patch available from openSUSE => (none)