Reported: 2018-06-14 23:24 CEST by David Walser
Status comment: Patch available from Ubuntu and upstream


Comment David Walser 2018-06-14 23:24:31 CEST
Ubuntu has issued an advisory today (June 14):

Ubuntu has backported patches and the upstream commit is linked from here:

Mageia 5 and Mageia 6 are also affected.
Comment 1 Marja Van Waes 2018-06-16 12:13:05 CEST
Assigning to all packagers collectively, since there is no registered maintainer for this package.

CC'ing the two last comitters.

Comment 2 David Walser 2018-06-17 19:56:37 CEST
Fedora has issued an advisory for this on June 16:
Comment 3 Nicolas Salguero 2018-06-19 11:37:49 CEST
Suggested advisory:

The updated packages fix a security vulnerability:

The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file. (CVE-2018-10360)


Updated package in 5/core/updates_testing:

from SRPMS:

Updated package in 6/core/updates_testing:

from SRPMS:

Comment 4 Len Lawrence 2018-06-19 12:37:11 CEST
Mageia 6, x86_64

No reproducers available.  Installed a couple of missing packages then updated them.  Clean install.

Shall look into the various options later but on the face of it file works fine.

Comment 5 Len Lawrence 2018-06-19 18:35:01 CEST
Mageia 5, x86_64

Packages updated cleanly.

This all looks OK.

Comment 6 Len Lawrence 2018-06-20 10:35:25 CEST
Mageia 6, x86_64

Ran a few more tests like those in comment 5.  The mga5 and mga6  systems have access to the same files.  The tests returned similar results.

OK for 64-bits.

Comment 7 claire robinson 2018-06-24 21:52:35 CEST
Validating. Advisoried.

Comment 8 Mageia Robot 2018-06-25 00:03:36 CEST
An update for this issue has been pushed to the Mageia Updates repository.


