Bug 30070

Summary: expat new security issues CVE-2022-2523[56], CVE-2022-2531[345]
Product: Mageia Reporter: Thomas Backlund <tmb>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: andrewsfarm, davidwhodgins, herman.viaene, sysadmin-bugs
Version: 8Keywords: advisory, validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA8-64-OK
Source RPM: expat CVE:
Status comment:
Attachments: Python script to run
testdata for testexpat.py

Description Thomas Backlund 2022-02-19 20:30:42 CET
https://seclists.org/oss-sec/2022/q1/150


SRPM:
expat-2.2.10-1.3.mga8.src.rpm


i586:
expat-2.2.10-1.3.mga8.i586.rpm
libexpat1-2.2.10-1.3.mga8.i586.rpm
libexpat-devel-2.2.10-1.3.mga8.i586.rpm


x86_64:
expat-2.2.10-1.3.mga8.x86_64.rpm
lib64expat1-2.2.10-1.3.mga8.x86_64.rpm
lib64expat-devel-2.2.10-1.3.mga8.x86_64.rpm
Comment 1 Herman Viaene 2022-02-21 11:15:19 CET
MGA8-64 Plasma on Lenoovo B50 in Dutch
No installation issues.
Followed wiki python testexpat.py, I will upload the test files.
$ python testexpat.py
Tested OK

so good to go.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 2 Herman Viaene 2022-02-21 11:15:55 CET
Created attachment 13156 [details]
Python script to run
Comment 3 Herman Viaene 2022-02-21 11:16:41 CET
Created attachment 13157 [details]
testdata for testexpat.py
Comment 4 David Walser 2022-02-21 23:47:01 CET
Ubuntu has issued an advisory for two of these issues today (February 21):
https://ubuntu.com/security/notices/USN-5288-1
Comment 5 Thomas Andrews 2022-02-22 04:21:25 CET
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2022-02-22 20:34:19 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 6 Mageia Robot 2022-02-22 21:16:28 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0081.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED

Comment 7 David Walser 2022-02-23 18:42:22 CET
Debian has issued an advisory for this on February 22:
https://www.debian.org/security/2022/dsa-5085