Bug 20782 - xstream new security issue CVE-2017-7957
Summary: xstream new security issue CVE-2017-7957
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Nicolas Lécureuil
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-05-04 12:36 CEST by David Walser
Modified: 2017-12-27 05:04 CET (History)
1 user (show)

See Also:
Source RPM: xstream-1.4.9-2.mga6.src.rpm
CVE: CVE-2017-7957
Status comment:


Attachments

Description David Walser 2017-05-04 12:36:45 CEST
Debian has issued an advisory on May 2:
https://www.debian.org/security/2017/dsa-3841

I don't know whether jenkins-xstream is affected.

Mageia 5 is also affected.
David Walser 2017-05-04 12:36:57 CEST

CC: (none) => geiger.david68210
Whiteboard: (none) => MGA5TOO

Comment 1 Nicolas Lécureuil 2017-05-15 23:53:48 CEST
Fixed in cauldron

Version: Cauldron => 5
Whiteboard: MGA5TOO => (none)

Nicolas Lécureuil 2017-05-15 23:53:56 CEST

CVE: (none) => CVE-2017-7957

Comment 2 David Walser 2017-05-23 04:10:45 CEST
It sounds like CVE-2017-2608 affects jenkins, or jenkins-xstream, or xstream:
http://openwall.com/lists/oss-security/2017/05/22/2
Comment 3 David Walser 2017-12-27 05:04:07 CET
We won't be fixing this type of package for Mageia 5.

Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.