+++ This bug was initially created as a clone of Bug #20525 +++ openSUSE has issued an advisory today (March 19): https://lists.opensuse.org/opensuse-updates/2017-03/msg00055.html The issue is fixed upstream in PuTTY 0.68. FileZilla also bundles PuTTY and is most likely affected. Upstream reference: http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-agent-fwd-overflow.html
Hmmmm! I tried to compile filezilla 3.25.2 for mga5 but we need to updating also nettle to 3.1 release: checking for NETTLE... no configure: error: nettle 3.1 greater was not found. You can get it from https://www.lysator.liu.se/~nisse/nettle/ error: Bad exit status from /home/iurt/rpmbuild/tmp/rpm-tmp.gJSKUH (%build) Note that filezilla 3.24.1 are now based on PuTTY 0.68 but this one needs also nettle 3.1.
Nothing currently uses nettle 3.0 in mga5 (everything uses 2.7), so upgrading the 3.0 to 3.1 wouldn't affect anything. Go for it.
Ping David.
David, just a note that the nettle you pushed in updates_testing from this: http://svnweb.mageia.org/packages?view=revision&revision=1109594 unfixes this: https://bugs.mageia.org/show_bug.cgi?id=17669
(In reply to David Walser from comment #4) > David, just a note that the nettle you pushed in updates_testing from this: > http://svnweb.mageia.org/packages?view=revision&revision=1109594 > > unfixes this: > https://bugs.mageia.org/show_bug.cgi?id=17669 what do you mean by that ?
CC: (none) => mageia
(In reply to Nicolas Lécureuil from comment #5) > (In reply to David Walser from comment #4) > > David, just a note that the nettle you pushed in updates_testing from this: > > http://svnweb.mageia.org/packages?view=revision&revision=1109594 > > > > unfixes this: > > https://bugs.mageia.org/show_bug.cgi?id=17669 > > > what do you mean by that ? Exactly what I said. We fixed CVE-2015-880[3-5] previously, but David dropped the patch for that when he updated it, but 3.1 didn't fix those issues, so the patch needs to be re-added.
David, if you still want to try and fix this, just update nettle to 3.3 (sync with mga6/Cauldron).
David, if you're still alive and want to take a crack at this, I updated nettle in Mageia 5 SVN to 3.3.
It looks like this also needs gnutls 3.4.15+, while we have 3.2.21 on Mageia 5, so we can't update this.
Status: NEW => RESOLVEDResolution: (none) => OLD