Bug 13483 - pulseaudio new security issue CVE-2014-3970
Summary: pulseaudio new security issue CVE-2014-3970
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/606884/
Whiteboard: MGA3TOO advisory MGA4-64-OK MGA4-32-O...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2014-06-04 18:01 CEST by David Walser
Modified: 2014-11-02 14:15 CET (History)
4 users (show)

See Also:
Source RPM: pulseaudio-5.0-0.20131220.1.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2014-06-04 18:01:29 CEST
A CVE was allocated for a security issue in PulseAudio today (June 4):
http://openwall.com/lists/oss-security/2014/06/04/16

Reproducible: 

Steps to Reproduce:
David Walser 2014-06-04 18:01:35 CEST

Whiteboard: (none) => MGA4TOO, MGA3TOO

Comment 1 Colin Guthrie 2014-06-04 22:38:13 CEST
Thanks David. I'll patch it as soon as the proposed patch or an alternative is accepted upstream.
Comment 2 David Walser 2014-07-30 20:17:21 CEST
Fedora has issued an advisory for this on July 9:
https://lists.fedoraproject.org/pipermail/package-announce/2014-July/136006.html

They had to rebuild every package built against the libs for their update.

URL: (none) => http://lwn.net/Vulnerabilities/606884/

Comment 3 Colin Guthrie 2014-07-30 21:12:58 CEST
We certainly won't need a rebuild for this issue. There was an ABI breakage for a while upstream and indeed we had it in cauldron before MGA4 came out, but I think the ABI breakage was only temporary so I it shouldn't have been a problem - perhaps they were just unluckly about whatever snapshot they used? Either way, this should be an easy enough fix.
Comment 4 Sander Lepik 2014-10-04 15:51:58 CEST
Ping..

CC: (none) => mageia

Comment 5 Sander Lepik 2014-11-01 10:46:54 CET
Ping #2, Colin, wake up :)
Comment 6 Colin Guthrie 2014-11-01 12:16:30 CET
Yeah I suck :)

Builds winging their way to MGA's 3 and 4 shortly. Will upload an advisory shortly.
Comment 7 Colin Guthrie 2014-11-01 15:17:00 CET
OK, advisory uploaded and packages built.


MGA3:

libpulseglib20-3.0-7.1.mga3.i586.rpm
libpulsecommon3.0-3.0-7.1.mga3.i586.rpm
libpulsecore3.0-3.0-7.1.mga3.i586.rpm
pulseaudio-utils-3.0-7.1.mga3.i586.rpm
pulseaudio-module-equalizer-3.0-7.1.mga3.i586.rpm
libpulseaudio0-3.0-7.1.mga3.i586.rpm
pulseaudio-module-x11-3.0-7.1.mga3.i586.rpm
pulseaudio-3.0-7.1.mga3.i586.rpm
pulseaudio-esound-compat-3.0-7.1.mga3.i586.rpm
pulseaudio-module-jack-3.0-7.1.mga3.i586.rpm
pulseaudio-module-bluetooth-3.0-7.1.mga3.i586.rpm
pulseaudio-module-lirc-3.0-7.1.mga3.i586.rpm
pulseaudio-module-xen-3.0-7.1.mga3.i586.rpm
libpulseaudio-devel-3.0-7.1.mga3.i586.rpm
pulseaudio-module-zeroconf-3.0-7.1.mga3.i586.rpm
pulseaudio-module-gconf-3.0-7.1.mga3.i586.rpm
pulseaudio-client-config-3.0-7.1.mga3.i586.rpm


pulseaudio-module-bluetooth-3.0-7.1.mga3.x86_64.rpm
lib64pulsecore3.0-3.0-7.1.mga3.x86_64.rpm
lib64pulsecommon3.0-3.0-7.1.mga3.x86_64.rpm
lib64pulseaudio-devel-3.0-7.1.mga3.x86_64.rpm
pulseaudio-3.0-7.1.mga3.x86_64.rpm
pulseaudio-esound-compat-3.0-7.1.mga3.x86_64.rpm
lib64pulseaudio0-3.0-7.1.mga3.x86_64.rpm
pulseaudio-client-config-3.0-7.1.mga3.x86_64.rpm
pulseaudio-module-x11-3.0-7.1.mga3.x86_64.rpm
pulseaudio-module-gconf-3.0-7.1.mga3.x86_64.rpm
pulseaudio-module-zeroconf-3.0-7.1.mga3.x86_64.rpm
pulseaudio-utils-3.0-7.1.mga3.x86_64.rpm
lib64pulseglib20-3.0-7.1.mga3.x86_64.rpm
pulseaudio-module-lirc-3.0-7.1.mga3.x86_64.rpm
pulseaudio-module-equalizer-3.0-7.1.mga3.x86_64.rpm
pulseaudio-module-xen-3.0-7.1.mga3.x86_64.rpm
pulseaudio-module-jack-3.0-7.1.mga3.x86_64.rpm



MGA 4

pulseaudio-module-gconf-5.0-1.mga4.i586.rpm
libpulseaudio0-5.0-1.mga4.i586.rpm
pulseaudio-module-zeroconf-5.0-1.mga4.i586.rpm
pulseaudio-module-x11-5.0-1.mga4.i586.rpm
libpulseaudio-devel-5.0-1.mga4.i586.rpm
pulseaudio-module-bluetooth-5.0-1.mga4.i586.rpm
pulseaudio-module-xen-5.0-1.mga4.i586.rpm
pulseaudio-utils-5.0-1.mga4.i586.rpm
pulseaudio-client-config-5.0-1.mga4.i586.rpm
pulseaudio-module-jack-5.0-1.mga4.i586.rpm
libpulsecommon5.0-5.0-1.mga4.i586.rpm
pulseaudio-esound-compat-5.0-1.mga4.i586.rpm
pulseaudio-5.0-1.mga4.i586.rpm
pulseaudio-module-lirc-5.0-1.mga4.i586.rpm
libpulsecore5.0-5.0-1.mga4.i586.rpm
libpulseglib20-5.0-1.mga4.i586.rpm
pulseaudio-module-equalizer-5.0-1.mga4.i586.rpm


pulseaudio-module-x11-5.0-1.mga4.x86_64.rpm
lib64pulsecore5.0-5.0-1.mga4.x86_64.rpm
pulseaudio-module-bluetooth-5.0-1.mga4.x86_64.rpm
pulseaudio-module-gconf-5.0-1.mga4.x86_64.rpm
pulseaudio-module-zeroconf-5.0-1.mga4.x86_64.rpm
lib64pulseglib20-5.0-1.mga4.x86_64.rpm
pulseaudio-module-lirc-5.0-1.mga4.x86_64.rpm
lib64pulsecommon5.0-5.0-1.mga4.x86_64.rpm
pulseaudio-esound-compat-5.0-1.mga4.x86_64.rpm
lib64pulseaudio0-5.0-1.mga4.x86_64.rpm
pulseaudio-client-config-5.0-1.mga4.x86_64.rpm
pulseaudio-5.0-1.mga4.x86_64.rpm
lib64pulseaudio-devel-5.0-1.mga4.x86_64.rpm
pulseaudio-utils-5.0-1.mga4.x86_64.rpm
pulseaudio-module-xen-5.0-1.mga4.x86_64.rpm
pulseaudio-module-jack-5.0-1.mga4.x86_64.rpm
pulseaudio-module-equalizer-5.0-1.mga4.x86_64.rpm

Assignee: mageia => qa-bugs
Whiteboard: MGA4TOO, MGA3TOO => MGA4TOO, MGA3TOO, has_advisory

Comment 8 Colin Guthrie 2014-11-01 15:17:57 CET
FWIW, For testing, I'd just make sure the package works. The bug is not easily explioitable and was not enabled by default. Provided it works for normal sound output, I'd be happy enough to just push it :)

CC: (none) => mageia

David Walser 2014-11-01 17:15:03 CET

Version: Cauldron => 4
Whiteboard: MGA4TOO, MGA3TOO, has_advisory => MGA3TOO advisory

Comment 9 Otto Leipälä 2014-11-01 17:27:45 CET
Little delay packaging this i was thinking i am slow but no :) i start to testing it.

CC: (none) => ozkyster

Comment 10 Otto Leipälä 2014-11-01 18:35:58 CET
Testing finished both releases and both arch as usual,i validate it so it will get pushed.
Sysadmins push this to updates.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs
Whiteboard: MGA3TOO advisory => MGA3TOO advisory MGA4-64-OK MGA4-32-OK MGA3-64-OK MGA3-32-OK

Comment 11 Mageia Robot 2014-11-02 14:15:13 CET
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2014-0440.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.