Bug 19579 - bubblewrap new security issue CVE-2016-8659
Summary: bubblewrap new security issue CVE-2016-8659
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Neal Gompa
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-10-13 12:33 CEST by David Walser
Modified: 2016-10-14 18:18 CEST (History)
0 users

See Also:
Source RPM: bubblewrap-0.1.2-mga6.src.rpm
CVE: CVE-2016-8659
Status comment:


Attachments

Description David Walser 2016-10-13 12:33:28 CEST
A CVE has been assigned for a security issue in bubblewrap:
http://www.openwall.com/lists/oss-security/2016/10/13/2

No fix is available yet.
Neal Gompa 2016-10-13 13:19:13 CEST

CVE: (none) => CVE-2016-8659
See Also: (none) => https://bugzilla.redhat.com/show_bug.cgi?id=1384393

Neal Gompa 2016-10-13 13:23:05 CEST

See Also: (none) => https://github.com/projectatomic/bubblewrap/issues/107

Comment 1 Neal Gompa 2016-10-14 18:18:28 CEST
A patch to mitigate the issue has been applied in bubblewrap-0.1.2-2.mga6.

See the following for details:

* https://github.com/projectatomic/bubblewrap/issues/107

* https://github.com/projectatomic/bubblewrap/pull/110

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.