Bug 12043 - qt4 new security issue CVE-2013-4549
Summary: qt4 new security issue CVE-2013-4549
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 3
Hardware: i586 Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/577579/
Whiteboard: advisory MGA3-64-OK MGA3-32-OK
Keywords: validated_update
Depends on:
Blocks: 12178
  Show dependency treegraph
 
Reported: 2013-12-18 19:00 CET by David Walser
Modified: 2014-01-17 01:42 CET (History)
5 users (show)

See Also:
Source RPM: qt4
CVE:
Status comment:


Attachments

Description David Walser 2013-12-18 19:00:31 CET
Ubuntu has issued an advisory on December 17:
http://www.ubuntu.com/usn/usn-2057-1/

qt5 in Cauldron may also be affected.

Reproducible: 

Steps to Reproduce:
David Walser 2013-12-18 19:00:44 CET

CC: (none) => balcaen.john
Whiteboard: (none) => MGA3TOO

David Walser 2013-12-18 20:13:27 CET

URL: (none) => http://lwn.net/Vulnerabilities/577579/

David Walser 2013-12-20 23:25:48 CET

Blocks: (none) => 11726

Comment 2 Nicolas Lécureuil 2013-12-23 21:43:03 CET
pushed in the BS for mga3
Nicolas Lécureuil 2013-12-23 21:48:06 CET

Assignee: mageia => qa-bugs

Comment 3 David Walser 2013-12-23 23:58:58 CET
OK, we have qt5 5.2 in Cauldron, so it's already fixed there.  Thanks Nicolas!

It looks like we have a qt5 5.0.2 packaged on Mageia 3, so that may need to be added to this.

Here's the advisory with just qt4 for now.

Advisory:
========================

Updated qt4 packages fixes security vulnerability:

It was discovered that QXmlSimpleReader in Qt incorrectly handled XML
entity expansion. An attacker could use this flaw to cause Qt applications
to consume large amounts of resources, resulting in a denial of service
(CVE-2013-4549).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4549
http://lists.qt-project.org/pipermail/announce/2013-December/000036.html
http://www.ubuntu.com/usn/usn-2057-1/
========================

Updated packages in core/updates_testing:
========================
qt4-common-4.8.5-1.2.mga3
libqtxml4-4.8.5-1.2.mga3
libqtscripttools4-4.8.5-1.2.mga3
libqtxmlpatterns4-4.8.5-1.2.mga3
libqtsql4-4.8.5-1.2.mga3
libqtnetwork4-4.8.5-1.2.mga3
libqtscript4-4.8.5-1.2.mga3
libqtgui4-4.8.5-1.2.mga3
libqtsvg4-4.8.5-1.2.mga3
libqttest4-4.8.5-1.2.mga3
libqthelp4-4.8.5-1.2.mga3
libqtclucene4-4.8.5-1.2.mga3
libqtcore4-4.8.5-1.2.mga3
libqt3support4-4.8.5-1.2.mga3
libqtopengl4-4.8.5-1.2.mga3
libqtdesigner4-4.8.5-1.2.mga3
libqtdbus4-4.8.5-1.2.mga3
libqtmultimedia4-4.8.5-1.2.mga3
qt4-qtdbus-4.8.5-1.2.mga3
libqtdeclarative4-4.8.5-1.2.mga3
qt4-qmlviewer-4.8.5-1.2.mga3
libqt4-devel-4.8.5-1.2.mga3
qt4-devel-private-4.8.5-1.2.mga3
qt4-xmlpatterns-4.8.5-1.2.mga3
qt4-qtconfig-4.8.5-1.2.mga3
qt4-doc-4.8.5-1.2.mga3
qt4-demos-4.8.5-1.2.mga3
qt4-examples-4.8.5-1.2.mga3
qt4-linguist-4.8.5-1.2.mga3
qt4-assistant-4.8.5-1.2.mga3
qt4-database-plugin-mysql-4.8.5-1.2.mga3
qt4-database-plugin-sqlite-4.8.5-1.2.mga3
qt4-database-plugin-tds-4.8.5-1.2.mga3
qt4-database-plugin-pgsql-4.8.5-1.2.mga3
qt4-graphicssystems-plugin-4.8.5-1.2.mga3
qt4-accessibility-plugin-4.8.5-1.2.mga3
qt4-designer-4.8.5-1.2.mga3
qt4-designer-plugin-webkit-4.8.5-1.2.mga3
qt4-designer-plugin-qt3support-4.8.5-1.2.mga3
qt4-qvfb-4.8.5-1.2.mga3
qt4-qdoc3-4.8.5-1.2.mga3

from qt4-4.8.5-1.2.mga3

CC: (none) => mageia
Version: Cauldron => 3
Whiteboard: MGA3TOO => (none)

David Walser 2013-12-24 00:00:49 CET

Blocks: 11726 => (none)

Comment 4 Dave Hodgins 2014-01-02 18:11:43 CET
Should we wait for qt5 to be updated too, or go ahead with testing qt4, and
use a new bug report for qt5?

CC: (none) => davidwhodgins

David Walser 2014-01-02 18:22:26 CET

Blocks: (none) => 12178

Comment 5 David Walser 2014-01-02 18:23:25 CET
I created Bug 12178 for qt5, so qt4 can be tested.
Comment 6 Dave Hodgins 2014-01-05 22:26:49 CET
The version in updates, and updates testing have the same release/version
numbers.

$ tree -ifa|grep qt4-demos
./release/qt4-demos-4.8.4-7.mga3.i586.rpm
./updates/qt4-demos-4.8.5-1.2.mga3.i586.rpm
./updates_testing/qt4-demos-4.8.5-1.2.mga3.i586.rpm

Whiteboard: (none) => feedback

Comment 7 David Walser 2014-01-05 22:54:16 CET
Thanks, qt4-4.8.5-1.3.mga3.src.rpm is building now.

Whiteboard: feedback => (none)

Comment 8 Dave Hodgins 2014-01-05 23:14:46 CET
Advisory added to svn. Waiting for local mirror to sync, before testing.

Whiteboard: (none) => advisory

Comment 9 Dave Hodgins 2014-01-07 19:28:05 CET
No poc, so just testing that all of the packages install cleanly and kde is ok.

Testing complete on Mageia 3 i586 and x86_64.

Someone from the sysadmin team please push 12043.adv to updates.

Keywords: (none) => validated_update
Whiteboard: advisory => advisory MGA3-64-OK MGA3-32-OK
CC: (none) => sysadmin-bugs

Comment 10 Thomas Backlund 2014-01-17 01:42:00 CET
Update pushed:
http://advisories.mageia.org/MGASA-2014-0009.html

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.