Bug 22102 - libxcursor new security issue CVE-2017-16612
Summary: libxcursor new security issue CVE-2017-16612
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA5TOO MGA5-64-OK MGA6-64-OK MGA5-32...
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2017-11-30 21:24 CET by David Walser
Modified: 2017-12-06 12:44 CET (History)
7 users (show)

See Also:
Source RPM: libxcursor-1.1.14-6.mga6.src.rpm
CVE: CVE-2017-16612
Status comment:


Attachments

Description David Walser 2017-11-30 21:24:05 CET
Ubuntu has issued an advisory on November 29:
https://usn.ubuntu.com/usn/usn-3501-1/

Mageia 5 and Mageia 6 are also affected.
David Walser 2017-11-30 21:24:10 CET

Whiteboard: (none) => MGA6TOO, MGA5TOO

Comment 1 Marja Van Waes 2017-11-30 21:29:33 CET
Assigning to all packagers collectively, since there is no registered maintainer for this package.

Assignee: bugsquad => pkg-bugs
CC: (none) => marja11

Comment 2 Nicolas Salguero 2017-12-01 10:12:05 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Heap overflows when parsing malicious files. (CVE-2017-16612)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16612
https://usn.ubuntu.com/usn/usn-3501-1/
========================

Updated packages in 5/core/updates_testing:
========================
lib(64)xcursor1-1.1.14-5.1.mga5
lib(64)xcursor-devel-1.1.14-5.1.mga5

from SRPMS:
libxcursor-1.1.14-5.1.mga5.src.rpm

Updated packages in 6/core/updates_testing:
========================
lib(64)xcursor1-1.1.14-6.1.mga6
lib(64)xcursor-devel-1.1.14-6.1.mga6

from SRPMS:
libxcursor-1.1.14-6.1.mga6.src.rpm

Version: Cauldron => 6
Status: NEW => ASSIGNED
Assignee: pkg-bugs => qa-bugs
CVE: (none) => CVE-2017-16612
CC: (none) => nicolas.salguero
Whiteboard: MGA6TOO, MGA5TOO => MGA5TOO

Comment 3 PC LX 2017-12-01 11:49:20 CET
Installed an tested without issues.

System: Mageia 5, x86_64, Plasma DE, Intel CPU, nVidia GPU with nvidia340 proprietary driver.

Since libxcursor is used by kwin and plasma-desktop, to test I simply restarted the Xorg server and session to be certain the new library was loaded and used. Also changed the cursor theme in KDE's systemsettings. No regressions noticed.

$ rpm -q lib64xcursor1
lib64xcursor1-1.1.14-5.1.mga5
$ uname -a
Linux marte 4.4.103-desktop-1.mga5 #1 SMP Thu Nov 30 12:44:39 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
$ urpmq --whatrequires lib64xcursor1 | egrep -v ^lib | sort -u
0ad
aseprite
chromium-browser-stable
fife
flash-player-plugin
freerdp
freshplayerplugin
gambas3-gb-sdl
gimp
godot
jogl2
kdebase4-runtime
kdebase4-workspace
kwin
lxqt-config
marco
mate-control-center
metacity
mousetweaks
muffin
openbox
plasma-desktop
sk1
spectrwm
spring
virtualbox
weston
wine64
x11-driver-video-intel
xcursorgen
xfce4-settings
xsetroot

CC: (none) => mageia

PC LX 2017-12-01 11:52:11 CET

Whiteboard: MGA5TOO => MGA5TOO MGA5-64-OK

Comment 4 Len Lawrence 2017-12-02 00:06:42 CET
Mageia 6 on x86_64 - Mate

Followed the lead of PC LX, comment 3.
Restarted the session and X.
Changed the mouse pointer via Mate settings -> Appearance -> Themes -> customize current theme.

Tried gimp, which appears in the list in comment 3.
$ strace gimp ManDogSun_Hackmann.jpg 2> trace
$ cat trace | grep libXcursor
open("/lib64/libXcursor.so.1", O_RDONLY|O_CLOEXEC) = 3
open("/usr/lib64/libXcursor.so.1.0.2", O_RDONLY) = 3

Whiteboard: MGA5TOO MGA5-64-OK => MGA5TOO MGA5-64-OK MGA6-64-OK
CC: (none) => tarazed25

Comment 5 Herman Viaene 2017-12-04 11:39:01 CET
MGA5-32 on Dell Latitude D600 Xfce
No installation issues.
Followed Comment 4 in Xfce settings and ran gimp, new cursor behaves OK.

Whiteboard: MGA5TOO MGA5-64-OK MGA6-64-OK => MGA5TOO MGA5-64-OK MGA6-64-OK MGA5-32-OK
CC: (none) => herman.viaene

Comment 6 Len Lawrence 2017-12-04 12:52:03 CET
Mageia 6 :: i586 in virtualbox

Updated the two libraries.
Changed the mouse pointer in Mate preferences -> look & feel
Restarted the session.

Everything running fine.  New mouse pointer in use.
Good for 32 bits.

Whiteboard: MGA5TOO MGA5-64-OK MGA6-64-OK MGA5-32-OK => MGA5TOO MGA5-64-OK MGA6-64-OK MGA5-32-OK MGA6-32-OK

Len Lawrence 2017-12-04 12:53:03 CET

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2017-12-05 20:47:45 CET

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 7 Mageia Robot 2017-12-06 12:44:02 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2017-0443.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.