| Summary: | botan2 new security issue CVE-2021-40529 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | andrewsfarm, herman.viaene, mageia, smelror, sysadmin-bugs |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | botan2-2.17.3-2.mga8.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2021-11-12 22:16:51 CET
David Walser
2021-11-12 22:17:11 CET
Status comment:
(none) =>
Fixed upstream in 2.18.2 Patch added in mga8:
src:
- botan2-2.17.3-2.1.mga8Status comment:
Fixed upstream in 2.18.2 =>
(none) Build failed: http://pkgsubmit.mageia.org/uploads/failure/8/core/updates_testing/20211214213810.neoclust.duvel.3026676/log/botan2-2.17.3-2.1.mga8/build.aarch64.0.20211214213850.log Assignee:
qa-bugs =>
mageia build OK Status comment:
Fixed upstream in 2.18.2 =>
(none) libbotan2_17-2.17.3-2.1.mga8 libbotan2-devel-2.17.3-2.1.mga8 botan2-2.17.3-2.1.mga8 python3-botan2-2.17.3-2.1.mga8 botan2-doc-2.17.3-2.1.mga8 from botan2-2.17.3-2.1.mga8.src.rpm MGA7-64 Plasma on Lenovo B50 in Dutch No installation issues. Test along bug 26955 Comment 6 $ botan --help Usage: botan <cmd> <cmd-options> All commands support --verbose --help --output= --error-output= --rng-type= --drbg-seed= Available commands: Encoders/Decoders: asn1print Decode and print file with ASN.1 Basic Encoding Rules (BER) and a lot more..... $ echo "Test File" > testbotan.txt $ botan base64_enc testbotan.txt > testbotancrypt.txt $ cat testbotancrypt.txt VGVzdCBGaWxlCg== $ botan base64_dec testbotancrypt.txtstbotancrypt.txt Test File $ python3 Python 3.8.12 (default, Sep 12 2021, 19:57:22) [GCC 10.3.0] on linux Type "help", "copyright", "credits" or "license" for more information. >>> import botan2 >>> tester = botan2.RandomNumberGenerator() >>> tested = tester.get(10) >>> print ("Random number is {}".format(tested)) Random number is b'\xfb\x11\x91\xa4\xa0\x03uWe\xf1' >>> quit() $ lynx /usr/share/doc/botan-2.17.3/handbook/index.html Looks OK, note that the file has changed name since bug 26955. CC:
(none) =>
herman.viaene Validating. Keywords:
(none) =>
validated_update
Thomas Backlund
2021-12-19 12:14:57 CET
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0563.html Resolution:
(none) =>
FIXED |