Bug 23143 - cairo new security issues CVE-2017-7475 and CVE-2017-9814
Summary: cairo new security issues CVE-2017-7475 and CVE-2017-9814
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Shlomi Fish
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-06-07 23:37 CEST by David Walser
Modified: 2019-11-06 13:28 CET (History)
2 users (show)

See Also:
Source RPM: cairo-1.14.10-1.mga6.src.rpm
CVE:
Status comment: Patches available from openSUSE


Attachments

Description David Walser 2018-06-07 23:37:20 CEST
openSUSE has issued an advisory on May 11:
https://lists.opensuse.org/opensuse-updates/2018-05/msg00036.html

Mageia 5 is also affected.
Comment 1 David Walser 2018-06-08 20:55:39 CEST
SUSE has issued an advisory on May 28:
http://lists.suse.com/pipermail/sle-security-updates/2018-May/004095.html

It fixes one additional issue that likely affects us as well.

Summary: cairo new security issue CVE-2017-9814 => cairo new security issues CVE-2017-7475 and CVE-2017-9814

Comment 2 Marja Van Waes 2018-06-08 21:28:31 CEST
Assigning to the registered maintainer.

CC: (none) => marja11
Assignee: bugsquad => shlomif

Comment 3 Shlomi Fish 2018-06-09 12:15:40 CEST
Where are the patches? I've been chasing links for many minutes now.q
Comment 4 David Walser 2018-06-09 17:06:39 CEST
replace-malloc-with-cairo-malloc.patch - CVE-2017-9814
cairo-get_bitmap_surface-bsc1036789-CVE-2017-7475.diff - CVE-2017-7475

https://build.opensuse.org/package/show/openSUSE:Leap:42.3:Update/cairo

Status comment: (none) => Patches available from openSUSE

Comment 5 David Walser 2018-07-06 17:31:17 CEST
openSUSE has issued an advisory for CVE-2017-9814 today (July 6):
https://lists.opensuse.org/opensuse-updates/2018-07/msg00002.html
Comment 6 Mike Rambo 2019-11-06 13:28:51 CET
Mageia 6 is EOL.

Resolution: (none) => OLD
CC: (none) => mrambo
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.