Bug 17012 - xscreensaver new security issue fixed upstream in 5.34 (CVE-2015-8025)
Summary: xscreensaver new security issue fixed upstream in 5.34 (CVE-2015-8025)
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/662785/
Whiteboard: MGA5-32-OK MGA5-64-OK advisory
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2015-10-25 16:56 CET by David Walser
Modified: 2015-11-05 23:47 CET (History)
5 users (show)

See Also:
Source RPM: xscreensaver-5.29-6.1.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2015-10-25 16:56:34 CET
A security issue in xscreensaver when used with XFce was reported:
http://openwall.com/lists/oss-security/2015/10/24/2

The issue was fixed in 5.34, with the patch linked in this message:
http://openwall.com/lists/oss-security/2015/10/25/1

Reproducible: 

Steps to Reproduce:
Comment 1 Nicolas Salguero 2015-10-26 11:00:43 CET
As fedora already provides version 5.33 while we have version 5.29 for Mga5 and because we have bug mga#15460, I have updated that version to 5.34 (and, for Cauldron, I replaced 5.33 by 5.34).
Comment 2 Nicolas Salguero 2015-10-26 11:14:18 CET
Suggested advisory:
========================

The updated xscreensaver packages fix a security issue when used, in some cases, with dual screen and unplugging one of them.
========================

Updated packages in core/updates_testing:
========================
i586:
xscreensaver-5.34-2.mga5.i586.rpm
xscreensaver-base-5.34-2.mga5.i586.rpm
xscreensaver-common-5.34-2.mga5.i586.rpm
xscreensaver-extrusion-5.34-2.mga5.i586.rpm
xscreensaver-gl-5.34-2.mga5.i586.rpm

x86_64:
xscreensaver-5.34-2.mga5.x86_64.rpm
xscreensaver-base-5.34-2.mga5.x86_64.rpm
xscreensaver-common-5.34-2.mga5.x86_64.rpm
xscreensaver-extrusion-5.34-2.mga5.x86_64.rpm
xscreensaver-gl-5.34-2.mga5.x86_64.rpm

Source RPMs:
xscreensaver-5.34-2.mga5.src.rpm

Status: NEW => ASSIGNED
CC: (none) => nicolas.salguero
Assignee: nicolas.salguero => qa-bugs

Comment 3 David Walser 2015-10-26 11:28:09 CET
Thanks Nicolas!  Don't forget to rebuild it in Cauldron since the release tag was bumped in mga5.
Comment 4 Nicolas Salguero 2015-10-26 11:32:03 CET
In fact, I began by Cauldron because switching from 5.33 to 5.34 was easier than switching from 5.29 to 5.34 (all the patches which had been updated to fit 5.33 applied as is in 5.34).
Comment 5 David Walser 2015-10-26 11:33:15 CET
Yes I see, but we have 1.mga6 and 2.mga5 right now, so it won't upgrade properly.
Comment 6 Nicolas Salguero 2015-10-26 11:39:15 CET
Oops, I missed that problem, sorry.  I rebuild in Cauldron with 2.mga6.
Comment 7 David Walser 2015-10-29 21:56:23 CET
CVE-2015-8025 assigned:
http://openwall.com/lists/oss-security/2015/10/29/12

Please update the advisory.

Summary: xscreensaver new security issue fixed upstream in 5.34 => xscreensaver new security issue fixed upstream in 5.34 (CVE-2015-8025)

Comment 8 David Walser 2015-11-02 21:02:58 CET
Debian-LTS has issued an advisory for this on October 31:
http://lwn.net/Vulnerabilities/662785/

URL: (none) => http://lwn.net/Vulnerabilities/662785/

Comment 9 Herman Viaene 2015-11-03 15:14:58 CET
MGA5-32 on Acer D620 Xfce
No installation issues.
It does not break anything apparently, but the screensaver does not seem to work. I put the time to 2 min, but after 3 min nothing had happened yet (even rebooting after the changes does not help). Only the black screen appears after its time-out. Switching it off completely works OK (and that's my preferred setting), so OK for me.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA5-32-OK

Comment 10 Len Lawrence 2015-11-04 00:55:50 CET
mga5 - x86-64 - Mate
default: xscreensaver-5.29-6.1
Updated to 5.34-2
Set the timeout to 1 minute and the screensaver launched on time and worked fine.

Will try a 32-bit VM tomorrow to check Herman's result.

CC: (none) => tarazed25

Comment 11 Len Lawrence 2015-11-04 09:50:02 CET
32-bit install in virtualbox on an x86_64 system.  Set a minute timeout for the screensaver and it worked fine.

Whiteboard: MGA5-32-OK => MGA5-32-OK MGA5-64-OK

Comment 12 Nicolas Salguero 2015-11-04 11:46:19 CET
The behavior described by Herman seems related to bug 15460.
Dave Hodgins 2015-11-05 22:13:02 CET

Keywords: (none) => validated_update
Whiteboard: MGA5-32-OK MGA5-64-OK => MGA5-32-OK MGA5-64-OK advisory
CC: (none) => davidwhodgins, sysadmin-bugs

Comment 13 Mageia Robot 2015-11-05 23:47:02 CET
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2015-0431.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.