| Summary: | libgda, libgda5.0 new security issue CVE-2021-39359 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | andrewsfarm, davidwhodgins, jani.valimaa, sysadmin-bugs |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | libgda5.0-5.2.9-3.mga8.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2021-12-31 19:28:44 CET
David Walser
2021-12-31 19:28:56 CET
Status comment:
(none) =>
Patch available from Fedora This is wally's baby. Assignee:
bugsquad =>
jani.valimaa libgda doesn't exist in mga8. libgda and libga5.0 fixed in cauldron. Updated cauldron pkgs: libgda-6.0.0-3.mga9 libgda5.0-5.2.10-2.mga9 Version:
Cauldron =>
8 Pushed fixed libgda5.0-5.2.9-3.1.mga8 to mga8 core/updates_testing. Please test. SRPMS: libgda5.0-5.2.9-3.1.mga8 RPMS: libgda5.0-5.2.9-3.1.mga8 lib(64)gda5.0_4-5.2.9-3.1.mga8 lib(64)gda5.0-devel-5.2.9-3.1.mga8 lib(64)gda-gir5.0-5.2.9-3.1.mga8 lib(64)gdaui-gir5.0-5.2.9-3.1.mga8 libgda5.0-postgres-5.2.9-3.1.mga8 libgda5.0-mysql-5.2.9-3.1.mga8 libgda5.0-bdb-5.2.9-3.1.mga8 libgda5.0-sqlite-5.2.9-3.1.mga8 Assignee:
jani.valimaa =>
qa-bugs
David Walser
2021-12-31 22:16:11 CET
Status comment:
Patch available from Fedora =>
(none) No previous updates, but a recursive search with urpmq revealed that the Gnome app Planner requires libgda5.0, or at least one of its dependencies. Checked my Gnome VirtualBox guest, and found that Planner was already installed, so used qarepo to update. No installation issues. Ran strace on planner, and found several references to libgda-related files. No obvious issues noted, though for the record I don't recall ever using the app. Then I took a look at the file list in drakrpm for libgda5.0, and found a bin for "gdaui-demo-5.0" Ran that in a terminal, and after several warnings about Gtk theme parsing errors regarding depreciated button borders, a small gui came up with a list of demos. Double-clicked on some to run them, and no issues were noted. Looks like this one is OK. Validating. Whiteboard:
(none) =>
MGA8-64-OK
Dave Hodgins
2022-01-03 03:02:50 CET
CC:
(none) =>
davidwhodgins An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2022-0005.html Status:
NEW =>
RESOLVED |