Bug 16689 - libidn new security issue CVE-2015-2059 affects curl and wget
Summary: libidn new security issue CVE-2015-2059 affects curl and wget
Status: RESOLVED WONTFIX
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/651768/
Whiteboard:
Keywords:
Depends on: 16342
Blocks:
  Show dependency treegraph
 
Reported: 2015-09-02 20:01 CEST by David Walser
Modified: 2015-09-04 15:37 CEST (History)
0 users

See Also:
Source RPM: curl, wget
CVE:
Status comment:


Attachments

Description David Walser 2015-09-02 20:01:58 CEST
+++ This bug was initially created as a clone of Bug #16342 +++

Upstream has released version 1.31 on July 8:
http://lists.gnu.org/archive/html/info-gnu/2015-07/msg00003.html

This updated version is currently considered a "beta," as it changes the behavior of an API, and they haven't yet committed to retaining that change going forward.  We probably shouldn't update it until they do so.  It fixes a security issue in applications that use the API in an unsafe manner.

It was announced on the oss-security list on July 6 that wget and curl are two applications that are affected:
http://openwall.com/lists/oss-security/2015/07/06/5

cURL's approach was to disable libidn support by default, which I have also done in Cauldron.  If we are able to update to a "fixed" version of libidn in the future, we can re-enable curl's libidn support in Cauldron at that time.  For stable releases, it doesn't sound like it will ever make sense to backport this change in libidn, so disabling curl's libidn support there seems to be the way to go.  I have checked this change into Mageia 4 and Mageia 5 SVN.

wget has implemented a change to mitigate the impact of this issue, regardless of what libidn does.  I have checked this patch into Mageia 4, Mageia 5, and Cauldron SVN.

Unfortunately, libidn 1.32 requires an updated gettext to build, and the patched wget won't build.
Comment 1 David Walser 2015-09-04 15:37:50 CEST
I can't fix this for Mageia 4.  Closing as WONTFIX.

Status: NEW => RESOLVED
Resolution: (none) => WONTFIX


Note You need to log in before you can comment on or make changes to this bug.