Bug 22743 - jgraphx new security issue CVE-2017-18197
Summary: jgraphx new security issue CVE-2017-18197
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Java Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-03-11 15:57 CET by David Walser
Modified: 2019-11-06 13:21 CET (History)
2 users (show)

See Also:
Source RPM: jgraphx-3.5.0.0-1.mga6.src.rpm
CVE:
Status comment: Fixed upstream in 3.7.6


Attachments

Description David Walser 2018-03-11 15:57:27 CET
openSUSE has issued an advisory on March 7:
https://lists.opensuse.org/opensuse-updates/2018-03/msg00010.html

Mageia 5 and Mageia 6 are also affected.
David Walser 2018-03-11 15:57:53 CET

Whiteboard: (none) => MGA6TOO
Status comment: (none) => Fixed upstream in 3.7.6

Comment 1 David Walser 2018-04-22 16:37:50 CEST
Fedora has issued an advisory for this on April 21:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/WYHPUXXDPFETWHX7CCJ4WTDU66UKIOVW/
Comment 2 David Walser 2019-01-01 05:00:18 CET
Updated to 3.9.3 in Cauldron by Stig-Ørjan.

Version: Cauldron => 6
Whiteboard: MGA6TOO => (none)
CC: (none) => smelror

Comment 3 Mike Rambo 2019-11-06 13:21:23 CET
Mageia 6 is EOL.

Status: NEW => RESOLVED
CC: (none) => mrambo
Resolution: (none) => OLD


Note You need to log in before you can comment on or make changes to this bug.