Bug 33314

Summary: bouncycastle new security issue CVE-2024-30171
Product: Mageia Reporter: Nicolas Salguero <nicolas.salguero>
Component: SecurityAssignee: Nicolas Lécureuil <mageia>
Status: NEW --- QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: marja11
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA9TOO
Source RPM: bouncycastle-1.77-1.mga10.src.rpm CVE: CVE-2024-30171
Status comment: Fixed upstream in 1.78.1

Description Nicolas Salguero 2024-06-19 10:05:32 CEST
openSUSE has issued an advisory on June 18:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/NCEDYUZRBIYFFW6ATWOW33BSWPBY2U52/

The problem is fixed in version 1.78.1.

Mageia 9 is also affected.
Nicolas Salguero 2024-06-19 10:06:07 CEST

Source RPM: (none) => bouncycastle-1.77-1.mga10.src.rpm
CVE: (none) => CVE-2024-30171
Status comment: (none) => Fixed upstream in 1.78.1
Whiteboard: (none) => MGA9TOO

Comment 1 Marja Van Waes 2024-06-20 21:16:27 CEST
Assigning to the registered bouncycastle maintainer

CC: (none) => marja11
Assignee: bugsquad => mageia