Bug 30058

Summary: kcron new security issue CVE-2022-24986
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: KDE maintainers <kde>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: mageia, nicolas.salguero
Version: 8   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: kcron-21.12.0-1.mga9.src.rpm CVE:
Status comment: Fixed upstream in 21.12.3

Description David Walser 2022-02-16 23:50:27 CET
KDE has issued an advisory today (February 16):
https://kde.org/info/security/advisory-20220216-1.txt

The issue is fixed upstream in 21.12.3.

Mageia 8 is also affected.
David Walser 2022-02-16 23:50:57 CET

Status comment: (none) => Fixed upstream in 21.12.3
Whiteboard: (none) => MGA8TOO

Nicolas Lécureuil 2022-02-17 00:52:18 CET

Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8
CC: (none) => mageia

Comment 1 David Walser 2022-02-17 00:54:47 CET
Fixed in kcron-21.12.0-2.mga9.
Comment 2 David Walser 2022-02-25 16:16:50 CET
Detailed analysis:
https://www.openwall.com/lists/oss-security/2022/02/25/3
Comment 3 Nicolas Salguero 2024-01-12 09:41:00 CET
Mageia 8 EOL

Resolution: (none) => OLD
CC: (none) => nicolas.salguero
Status: NEW => RESOLVED