| Summary: | python-imageio downloads vulnerable freeimage library | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, geiger.david68210, sysadmin-bugs, yvesbrungard |
| Version: | 9 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA9-64-OK | ||
| Source RPM: | python-imageio-2.9.0-4.mga9.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2022-10-24 17:18:24 CEST
David Walser
2022-10-24 17:18:32 CEST
Whiteboard:
(none) =>
MGA8TOO Assigning to the Python maintainers in advance. It can be revived when the necessary info becomes available (and noticed). Assignee:
bugsquad =>
python
David Walser
2022-10-26 15:10:08 CEST
Status:
NEEDINFO =>
NEW Removing Mageia 8 from whiteboard due to EOL! Whiteboard:
MGA8TOO =>
MGA9TOO Hello, I created a patch which raise an error when downloading is launched, saying "Mageia does not allow to install external binary". I removed also the commands imageio_download_bin and imageio_remove_bin as in Fedora. Done in Cauldron Whiteboard:
MGA9TOO =>
(none) Submitting: SRPMS python-imageio-2.22.4-1.1.mga9 RPMS: python3-imageio-2.22.4-1.1.mga9 Assignee:
python =>
qa-bugs I am not sure if the second link in comment#0 issues are fixed by the new packages so I only include the first in advisory text and reference Keywords:
(none) =>
advisory, feedback (In reply to katnatek from comment #5) > I am not sure if the second link in comment#0 issues are fixed by the new > packages so I only include the first in advisory text and reference Hi, the second link is about libraries downloaded with the previous commands. As we don't download anything anymore, this is no more our concern. And, yes, in fact, we don't provide a fix for this. RH mageia 9 x86_64
LC_ALL=C urpmi python3-imageio
installing python3-imageio-2.22.4-1.1.mga9.noarch.rpm from //home/katnatek/qa-testing/x86_64
Preparing... ##################################################################################################
1/1: python3-imageio ##################################################################################################
Create the example in https://github.com/imageio/imageio
Run the example
A jpg file named chelsea.jpg is created
Open the image with gwenview and gimp and look OK
I like a way to confirm the issue is fixed, but I trust in papoteurKeywords:
feedback =>
(none) Validating. CC:
(none) =>
sysadmin-bugs An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0244.html Status:
NEW =>
RESOLVED |