Bug 30549

Summary: ncurses new security issue CVE-2022-29458
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Base system maintainers <basesystem>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: minor    
Priority: Normal CC: johnwhitemail25, marja11, nicolas.salguero
Version: 8   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: ncurses-6.2-20201205.1.mga8.src.rpm CVE:
Status comment: Fixed upstream in 6.3-20220416
Bug Depends on: 31792    
Bug Blocks:    

Description David Walser 2022-06-14 15:20:34 CEST
Ubuntu has issued an advisory today (June 14):
https://ubuntu.com/security/notices/USN-5477-1

The issue is fixed upstream in 6.3-20220416.

The issue is so minimal, we could just patch it in SVN for now.
David Walser 2022-06-14 15:20:45 CEST

Status comment: (none) => Fixed upstream in 6.3-20220416

Comment 1 Marja Van Waes 2022-06-15 18:54:01 CEST
No registered maintainer 

[marja@T420cauldron64 ~]$ urpmq --requires-recursive basesystem-minimal | grep ncurses
lib64ncurses6
lib64ncursesw6
ncurses
[marja@T420cauldron64 ~]$

So assigning to the base system maintainers.

Assignee: bugsquad => basesystem
CC: (none) => marja11

Comment 2 David Walser 2022-08-12 18:44:32 CEST
openSUSE has issued an advisory for this on August 9:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/E4T4W6ZU3ABMUYO2SARACMFBR2F2VQLS/
Comment 3 David Walser 2022-10-31 15:19:42 CET
Debian-LTS has issued an advisory for this on October 29:
https://www.debian.org/lts/security/2022/dla-3167
David Walser 2023-06-16 00:25:49 CEST

Depends on: (none) => 31792

Comment 4 David Walser 2023-06-16 00:26:00 CEST
Ubuntu has issued an advisory for this on May 23:
https://ubuntu.com/security/notices/USN-6099-1
Comment 5 JohnWhite JohnWhite 2023-09-27 14:58:12 CEST Comment hidden (spam)

CC: (none) => johnwhitemail25

Comment 6 Nicolas Salguero 2024-01-12 09:54:46 CET
Mageia 8 EOL

Resolution: (none) => OLD
Status: NEW => RESOLVED
CC: (none) => nicolas.salguero