Bug 31505

Summary: opusfile new security issue CVE-2022-47021
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: major    
Priority: Normal CC: andrewsfarm, davidwhodgins, geiger.david68210, sysadmin-bugs
Version: 8Keywords: advisory, validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA8-64-OK
Source RPM: opusfile-0.12-3.mga9.src.rpm CVE:
Status comment:

Description David Walser 2023-02-03 01:56:32 CET
Fedora has issued an advisory today (February 2):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/4LIKBLOE433RA44YTYUZLED4IOWJG5DV/

Mageia 8 is also affected.
David Walser 2023-02-03 01:56:49 CET

Status comment: (none) => Patches available from upstream and Fedora
Whiteboard: (none) => MGA8TOO

Comment 1 David GEIGER 2023-02-04 16:10:00 CET
Done for both mga8 and Cauldron!

CC: (none) => geiger.david68210

Comment 2 David Walser 2023-02-04 16:18:03 CET
lib64opusfile0-0.12-1.1.mga8
lib64opusfile-devel-0.12-1.1.mga8

from opusfile-0.12-1.1.mga8.src.rpm

Assignee: bugsquad => qa-bugs
Status comment: Patches available from upstream and Fedora => (none)
Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)

Comment 3 Thomas Andrews 2023-02-06 00:58:38 CET
Tested in a VirtualBox mga8-64 Plasma guest. No installation issues.

urpmq --whatrequires lib64opusfile0 produces a relatively short list, with one of the results a game called "Taisei." 

I used "strace -o opus.txt taipei" and played the game, getting killed rather quickly, then examined the resulting opus.txt file. The search found one call to "/lib64/libopusfile.so.0" 

Going to call this OK. Validating.

Keywords: (none) => validated_update
Whiteboard: (none) => MGA8-64-OK
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2023-02-06 21:22:09 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 4 Mageia Robot 2023-02-07 01:09:06 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0042.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED