Bug 23495 - pango new security issue CVE-2018-15120
Summary: pango new security issue CVE-2018-15120
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Rémi Verschelde
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-08-28 22:22 CEST by David Walser
Modified: 2018-08-30 14:55 CEST (History)
0 users

See Also:
Source RPM: pango-1.40.6-1.1.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2018-08-28 22:22:21 CEST
Ubuntu has issued an advisory on August 22:
https://usn.ubuntu.com/3750-1/
Comment 1 Rémi Verschelde 2018-08-30 14:50:55 CEST
Working on this.

Assignee: bugsquad => rverschelde

Comment 2 Rémi Verschelde 2018-08-30 14:55:46 CEST
The patch for CVE-2018-15120 is on the pango/pango-emoji.c file, which is not present in our version 1.40.6.

It seems that the feature was added in 1.40.8, so we're safe: https://github.com/GNOME/pango/blob/1.40.8/NEWS

Cauldron ships 1.42.4 already so it's good too.

Status: NEW => RESOLVED
Resolution: (none) => INVALID


Note You need to log in before you can comment on or make changes to this bug.