Bug 23007 - p7zip has a vulnerability CVE-2017-17969
Summary: p7zip has a vulnerability CVE-2017-17969
Status: RESOLVED DUPLICATE of bug 22523
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal minor
Target Milestone: ---
Assignee: David GEIGER
QA Contact: Sec team
URL: https://www.cvedetails.com/vulnerabil...
Whiteboard:
Keywords: UPSTREAM
Depends on:
Blocks:
 
Reported: 2018-05-08 20:02 CEST by Jybz
Modified: 2018-05-09 22:40 CEST (History)
2 users (show)

See Also:
Source RPM: p7zip
CVE:
Status comment:


Attachments

Description Jybz 2018-05-08 20:02:36 CEST
Hi all,

p7zip is in version 16.02-4.mga7 for the cauldron, and people recently discovered a vulnerability and suggest to update p7zip to version 18.
<Sophie> 16.02-4.mga7 // core-release (Mga, cauldron, x86_64)
<Sophie> 16.02-4.mga7 // core-release (Mga, cauldron, i586)

The great sophie told me daviddavid is in charge.
<Sophie> For Mageia (p7zip): daviddavid

Good evening !
Jibz
Comment 1 David GEIGER 2018-05-08 20:21:24 CEST
Ok, and where is the 18 release?

CC: (none) => geiger.david68210

Comment 2 Jybz 2018-05-08 20:44:07 CEST
Meh...

You are right, there is no code available now for Linux...
https://sourceforge.net/p/p7zip/discussion/383043/thread/fa143cf2/?limit=25#2325
It seems their linux developer is not responding for months.

So, do we close this bug report ?
Comment 3 Marja Van Waes 2018-05-09 09:18:19 CEST
(In reply to David GEIGER from comment #1)
> Ok, and where is the 18 release?

(In reply to J-B B from comment #2)
> Meh...
> 
> You are right, there is no code available now for Linux...
> https://sourceforge.net/p/p7zip/discussion/383043/thread/fa143cf2/
> ?limit=25#2325
> It seems their linux developer is not responding for months.
> 
> So, do we close this bug report ?

No, afaik the vulnerabilities solved by version 18 exist in Linux, too.

Btw, Debian seems to have a patch for CVE-2017-17969
https://sourceforge.net/p/p7zip/bugs/204/
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=888297

CVE-2018-5996 sees to be for 7zip-rar only... we don't have that, do we?
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=888314

Keywords: (none) => UPSTREAM
CC: (none) => marja11
QA Contact: (none) => security
See Also: (none) => https://sourceforge.net/p/p7zip/bugs/204/, http://bugs.debian.org/888297
Summary: p7zip has a vulnerability => p7zip has a vulnerability CVE-2017-17969
Assignee: bugsquad => geiger.david68210
Component: RPM Packages => Security

Comment 4 David Walser 2018-05-09 11:55:36 CEST
Jibz, if you had stayed on IRC longer I'd have told you the RAR bugs (CVE-2018-5996 and CVE-2018-10115) don't affect us (Bug 22613).  Also, please search bugzilla first as we already fixed CVE-2017-17969.

*** This bug has been marked as a duplicate of bug 22523 ***

Status: NEW => RESOLVED
Resolution: (none) => DUPLICATE

Comment 5 Jybz 2018-05-09 13:13:01 CEST
Hi David,

Sorry, I sleep at night and I turn the computer off.
And I searched on bugzilla, try by yourself,
no result for p7zip, and no bug 22523 nor 22613 for the research p7.
Your message looks like a reproach, I'm sorry to annoy.
Comment 6 David Walser 2018-05-09 14:46:53 CEST
It's not a reproach, but I need you to learn how to search bugzilla if you're going to report security issues (which is quite welcome, in fact one of the CVEs in one of the links you posted on IRC I wasn't previously aware of).  You have to do advanced search and at least make sure FIXED also gets searched (hold the Ctrl key when you click on FIXED).  You would have also needed to select INVALID to be able to find the RAR issue I had previously filed a bug for.
Comment 7 Marja Van Waes 2018-05-09 22:40:05 CEST
(In reply to J-B B from comment #5)

> And I searched on bugzilla, try by yourself,
> no result for p7zip, and no bug 22523 nor 22613 for the research p7.

I didn't search well, either, I only did a quick search (using the small search bos at the top of this screen) for 

     CVE-2017-17969

because I wrongly assumed this issue couldn't already have been fixed.

I should have done 

    ALL CVE-2017-17969

Putting "ALL" before the search strings finds all related bugs, regardless of whether they're open, fixed, invalid or whatnot.

   ALL p7zip

returns 12 bug reports, including the ones we should have seen ;-)

Note You need to log in before you can comment on or make changes to this bug.