Bug 14986 - mpfr new security issue CVE-2014-9474
Summary: mpfr new security issue CVE-2014-9474
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/628832/
Whiteboard: has_procedure advisory MGA4-64-OK MGA...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2015-01-08 18:06 CET by David Walser
Modified: 2015-01-09 17:44 CET (History)
2 users (show)

See Also:
Source RPM: mpfr-3.1.2-2.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2015-01-08 18:06:58 CET
Fedora has issued an advisory on December 15:
https://lists.fedoraproject.org/pipermail/package-announce/2015-January/147737.html

Patched packages uploaded for Mageia 4 and Cauldron.

Advisory:
========================

Updated mpfr packages fix security vulnerability:

A buffer overflow was reported in mpfr. This is due to incorrect GMP
documentation for mpn_set_str about the size of a buffer (CVE-2014-9474).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9474
https://lists.fedoraproject.org/pipermail/package-announce/2015-January/147737.html
========================

Updated packages in core/updates_testing:
========================
libmpfr4-3.1.2-2.1.mga4
libmpfr-devel-3.1.2-2.1.mga4
libmpfr-static-devel-3.1.2-2.1.mga4

from mpfr-3.1.2-2.1.mga4.src.rpm

Reproducible: 

Steps to Reproduce:
Comment 1 Herman Viaene 2015-01-09 11:32:07 CET
MGA4-64 on HP Probook 6555b KDE
No installation issues.
urpmq --whatrequires lib64mpfr4
shows a.o. genius
I installed genius, and ran it with strace
gave it 30*70+67^3.0 to calculate , returned = 302863.0
trace shows : open("/lib64/libmpfr.so.4"

CC: (none) => herman.viaene
Whiteboard: (none) => MGA4-64-OK

Comment 2 Herman Viaene 2015-01-09 11:43:20 CET
MGA4-32 on AcerD620 Xfce
Confirm results as per Comment 1

Whiteboard: MGA4-64-OK => MGA4-64-OK MGA4-32-OK

Comment 3 claire robinson 2015-01-09 16:19:11 CET
Genius, well done Herman.

Validating. Advisory uploaded.

Please push to 4 updates

Thanks

Keywords: (none) => validated_update
Whiteboard: MGA4-64-OK MGA4-32-OK => has_procedure advisory MGA4-64-OK MGA4-32-OK
CC: (none) => sysadmin-bugs

Comment 4 Mageia Robot 2015-01-09 17:44:54 CET
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2015-0021.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.