Bug 22987 - opencv new security issues CVE-2017-17760, CVE-2017-18009, CVE-2017-1000450, and more
Summary: opencv new security issues CVE-2017-17760, CVE-2017-18009, CVE-2017-1000450, ...
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Shlomi Fish
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-05-03 18:57 CEST by David Walser
Modified: 2019-11-06 13:27 CET (History)
2 users (show)

See Also:
Source RPM: opencv-2.4.12.3-5.mga6.src.rpm
CVE:
Status comment: Patches available from Fedora and openSUSE


Attachments

Description David Walser 2018-05-03 18:57:41 CEST
Fedora has issued an advisory today (May 3):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/VR5DCLWTSQMPCTUPXE4GMJSMGZJ7IE53/

CVE-2017-1000450 certainly affects Mageia 5 and Mageia 6, but it's not clear if CVE-2017-17760 affects either one.  The issues were fixed in 3.4.0, so Cauldron is not affected.
Comment 1 Marja Van Waes 2018-05-03 21:07:33 CEST
Assigning to the registered maintainer.

CC: (none) => marja11
Assignee: bugsquad => shlomif

David Walser 2018-05-04 08:25:09 CEST

Status comment: (none) => Patches available from Fedora

Comment 2 David Walser 2018-06-07 23:40:29 CEST
openSUSE advisories from May 12, 23, and 28, fix these issues and several more:
https://lists.opensuse.org/opensuse-updates/2018-05/msg00038.html
https://lists.opensuse.org/opensuse-updates/2018-05/msg00089.html
https://lists.opensuse.org/opensuse-updates/2018-05/msg00128.html

CVE-2016-1516 CVE-2016-1517
CVE-2017-12597 CVE-2017-12598
CVE-2017-12599 CVE-2017-12600 CVE-2017-12601
CVE-2017-12602 CVE-2017-12603 CVE-2017-12604
CVE-2017-12605 CVE-2017-12606 CVE-2017-12862
CVE-2017-12863 CVE-2017-12864 CVE-2017-14136
CVE-2017-18009 CVE-2018-5268 CVE-2018-5269

are the new issues.
Comment 3 David Walser 2018-06-15 18:51:22 CEST
openSUSE has issued an advisory today (June 15) for CVE-2017-18009:
https://lists.opensuse.org/opensuse-updates/2018-06/msg00086.html

Summary: opencv new security issues CVE-2017-17760 and CVE-2017-1000450 => opencv new security issues CVE-2017-17760, CVE-2017-18009, CVE-2017-1000450, and more
Status comment: Patches available from Fedora => Patches available from Fedora and openSUSE

Comment 4 Mike Rambo 2019-11-06 13:27:30 CET
Mageia 6 is EOL.

Resolution: (none) => OLD
CC: (none) => mrambo
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.