| Summary: | tcl-snack new security issue CVE-2012-6303 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Normal | CC: | sysadmin-bugs, tmb, wassi |
| Version: | 2 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/532544/ | ||
| Whiteboard: | has_procedure mga2-64-OK MGA2-32-OK | ||
| Source RPM: | snack-2.2.10-10.mga2.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2013-01-14 23:38:26 CET
claire robinson
2013-01-15 01:40:32 CET
Whiteboard:
(none) =>
has_procedure Snack has a testsuite too David, is it used here? Testing complete mga2 64 Saved the PoC as wavesurfer.pl and created the crafted wav with $ perl wavesurfer.pl Before ------ $ cd /usr/share/doc/tcl-snack/ $ ./widget.tcl Unable to play sound due to it requiring /dev/sound/dsp which I think is OSS, but running with soundwrapper corrects that. $ soundwrapper ./widget.tcl Opening the crafted wav causes a backtrace. Python-snack doesn't seem affected. $ cd /usr/share/doc/python-snack/ $ soundwrapper ./widget.py After ----- No backtrace Hardware:
i586 =>
All (In reply to comment #1) > Snack has a testsuite too David, is it used here? No. Testing complete on mga2, i586. Before ------ $ cd /usr/share/doc/tcl-snack/ $ ./widget.tcl $ soundwrapper ./widget.tcl Opening the crafted wav file causes a segmentation fault. $ cd /usr/share/doc/python-snack/ $ soundwrapper ./widget.py Opening the crafted wav file causes a segmentation fault also for the python version. After ----- No segmentation fault (for either version) when opening the crafted file. ---- Validating No linking needed according to depcheck. See comment 0 for SRPM & Advisory. Could sysadmin please push from core/updates_testing to core/updates. Thank you! Keywords:
(none) =>
validated_update Update pushed: https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0017 Status:
NEW =>
RESOLVED |