Bug 31650

Summary: xfig new security issue CVE-2021-40241
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: andrewsfarm, davidwhodgins, geiger.david68210, herman.viaene, sysadmin-bugs
Version: 8Keywords: advisory, validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA8-64-OK
Source RPM: xfig-3.2.8b-1.mga9.src.rpm CVE:
Status comment:

Description David Walser 2023-03-09 17:39:44 CET
Debian-LTS has issued an advisory on March 5:
https://www.debian.org/lts/security/2023/dla-3353

Mageia 8 is also affected.
David Walser 2023-03-09 17:39:56 CET

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Patch available from Debian

Comment 1 Lewis Smith 2023-03-09 20:07:27 CET
Xfig has no particular maintainer, so assigning this update globally.

Assignee: bugsquad => pkg-bugs

Comment 2 David GEIGER 2023-03-10 06:08:49 CET
Patch added for mga8!

But CVE-2021-40241 is already fixed in 3.2.8b release for Cauldron.

CC: (none) => geiger.david68210

Comment 3 David Walser 2023-03-10 12:22:52 CET
xfig-3.2.7b-1.1.mga8

from xfig-3.2.7b-1.1.mga8.src.rpm

Status comment: Patch available from Debian => (none)
Version: Cauldron => 8
Assignee: pkg-bugs => qa-bugs
Whiteboard: MGA8TOO => (none)

Comment 4 Herman Viaene 2023-03-12 16:58:57 CET
MGA8-64 MATE on Acer Aspire 5253
No installation issues.
I could open xfig, draw some shapes, saved the file and re-opened it. All my scriblings were there.
So it seems to work. For my own curiosity I tried to open/import this file into some other program. Tried LODraw and Inkscape, but all failed. But this is probably due to my inexperience in such matters.
So giving the OK based on the fact that drawing works OK and it can re-open its own files.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA8-64-OK

Comment 5 Thomas Andrews 2023-03-12 22:58:36 CET
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2023-03-14 20:53:15 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 6 Mageia Robot 2023-03-18 23:18:33 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0101.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED