| Summary: | libcap new security issues CVE-2023-2602 and CVE-2023-2603 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | andrewsfarm, davidwhodgins, herman.viaene, nicolas.salguero, sysadmin-bugs, troy28217, zetisonapi |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | libcap-2.46-1.mga8.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2023-05-18 18:26:51 CEST
David Walser
2023-05-18 18:27:05 CEST
Whiteboard:
(none) =>
MGA8TOO Another package with no one maintainer in view, so this is to assign globally. Assignee:
bugsquad =>
pkg-bugs Ubuntu has issued an advisory for this on June 14: https://ubuntu.com/security/notices/USN-6166-1 Suggested advisory: ======================== The updated packages fix security vulnerabilities: A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory. (CVE-2023-2602) A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB. (CVE-2023-2603) References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2602 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2603 https://www.openwall.com/lists/oss-security/2023/05/15/4 https://sites.google.com/site/fullycapable/release-notes-for-libcap#h.iuvg7sbjg8pe https://www.openwall.com/lists/oss-security/2023/05/16/2 https://ubuntu.com/security/notices/USN-6166-1 ======================== Updated packages in core/updates_testing: ======================== lib(64)cap2-2.46-1.1.mga8 lib(64)cap-devel-2.46-1.1.mga8 libcap-utils-2.46-1.1.mga8 pam_cap-2.46-1.1.mga8 from SRPM: libcap-2.46-1.1.mga8.src.rpm Version:
Cauldron =>
8 MGA8-64 MATE on Acer Aspire 5253 No installation issues Ref bug 3938 (a bit beyond my level) # capsh --chroot=/ -- -c /bin/pwd / # getcap -v py3requests_test2.py py3requests_test2.py # getpcaps py3requests_test2.py py3requests_test2.py: =ep Giving the OK on the basis it looks reasonable. Whiteboard:
(none) =>
MGA8-64-OK Validating. Advisory in comment 3. CC:
(none) =>
andrewsfarm, sysadmin-bugs
Dave Hodgins
2023-06-27 22:36:40 CEST
CC:
(none) =>
davidwhodgins An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2023-0205.html Status:
ASSIGNED =>
RESOLVED Video games can be a great way to connect with friends and family. Many games allow players to compete or cooperate with each other online, and they can be a great way to stay in touch with loved ones who live far away. https://dinosaurgameoffline.com CC:
(none) =>
zetisonapi *** Bug 32559 has been marked as a duplicate of this bug. *** Redactle uses less Wikipedia articles, which is beneficial. Wikipedia's top 10,000 Level 4 articles form this list. That's little compared to Wikipedia's 6 million articles. You couldn't write about classical concerts with raucous audiences or Fake Bread, but you could discuss Greco-Roman wrestling, algebraic topology, and Ralph Waldo Emerson. https://ricepuritytest2024.com/ CC:
(none) =>
troy28217 |