Bug 23251 - pdfbox new security issues CVE-2018-8036, CVE-2018-11797, and CVE-2019-0228
Summary: pdfbox new security issues CVE-2018-8036, CVE-2018-11797, and CVE-2019-0228
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Java Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on: 28708
Blocks:
  Show dependency treegraph
 
Reported: 2018-06-29 15:16 CEST by David Walser
Modified: 2021-07-01 18:16 CEST (History)
2 users (show)

See Also:
Source RPM: pdfbox-2.0.9-2.mga7.src.rpm
CVE: CVE-2019-0228
Status comment: Fixed upstream in 2.0.16


Attachments

Description David Walser 2018-06-29 15:16:12 CEST
Apache has issued an advisory today (June 29):
http://openwall.com/lists/oss-security/2018/06/29/1

The issue is fixed upstream in 1.8.14.

Mageia 5 and Mageia 6 are also affected.
David Walser 2018-06-29 15:16:26 CEST

Whiteboard: (none) => MGA6TOO
Status comment: (none) => Fixed upstream in 1.8.14

Comment 1 David Walser 2018-06-29 23:46:44 CEST
Updated advisory with references:
http://openwall.com/lists/oss-security/2018/06/29/2
Comment 2 David Walser 2018-09-07 19:08:02 CEST
openSUSE has issued an advisory for this today (September 7):
https://lists.opensuse.org/opensuse-updates/2018-09/msg00028.html
Comment 3 David Walser 2018-10-05 22:35:34 CEST
Apache has issued an advisory today (October 5):
https://www.openwall.com/lists/oss-security/2018/10/05/4

The issue is fixed upstream in 1.8.16 and 2.0.12.

Summary: pdfbox new security issue CVE-2018-8036 => pdfbox new security issues CVE-2018-8036 and CVE-2018-11797
Source RPM: pdfbox-1.8.13-1.mga7.src.rpm => pdfbox-2.0.9-2.mga7.src.rpm
Status comment: Fixed upstream in 1.8.14 => Fixed upstream in 1.8.16 and 2.0.12

Comment 4 David Walser 2018-10-24 17:54:59 CEST
openSUSE has issued an advisory for this today (October 24):
https://lists.opensuse.org/opensuse-updates/2018-10/msg00157.html
David Walser 2019-06-23 19:31:08 CEST

Whiteboard: MGA6TOO => MGA7TOO, MGA6TOO

Comment 5 David Walser 2019-12-23 23:41:42 CET
Fedora has issued an advisory for this on September 9:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/POPOGHJ5CVMUVCRQU7APBAN5IVZGZFDX/

It adds one new CVE, fixed upstream in 2.0.16.

Again this was fixed in Cauldron with the CVEs in the commit message, but no bug for the new CVE.

Whiteboard: MGA7TOO, MGA6TOO => (none)
Status comment: Fixed upstream in 1.8.16 and 2.0.12 => Fixed upstream in 2.0.16
Version: Cauldron => 7
CC: (none) => geiger.david68210
Summary: pdfbox new security issues CVE-2018-8036 and CVE-2018-11797 => pdfbox new security issues CVE-2018-8036, CVE-2018-11797, and CVE-2019-0228

Zombie Ryushu 2020-12-23 08:14:33 CET

CVE: (none) => CVE-2019-0228
CC: (none) => zombie_ryushu

David Walser 2021-03-30 23:27:13 CEST

Depends on: (none) => 28682

Nicolas Lécureuil 2021-04-03 00:26:21 CEST

Depends on: (none) => 28708

Nicolas Lécureuil 2021-04-03 00:27:57 CEST

Depends on: 28682 => (none)

Comment 6 David Walser 2021-07-01 18:16:52 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.