Fedora has issued an advisory on October 30: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/F7UTCHIMQ32VOARS5O67QMCVHTYAPTMM/
CC: (none) => geiger.david68210
Assigning to all packagers collectively, since there is no registered maintainer for this package.
CC: (none) => marja11
(In reply to Marja Van Waes from comment #1) > Assigning to all packagers collectively, since there is no registered > maintainer for this package. Now really assigning :-/
Assignee: bugsquad => pkg-bugs
Fixed for mga6 updating to latest 2.3.2 release!
Advisory: ======================== Updated gdal packages fix security vulnerability: A flaw was found in gdal up to version 2.3.0. A Heap-buffer-overflow in GTiffOddBitsBand::IReadBlock. A flaw was found in gdal. A Heap-buffer-overflow in NITFRasterBand::Unpack. A flaw was found in gdal up to version 2.3.0. An Index-out-of-bounds in CPLErrorSetState. References: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/F7UTCHIMQ32VOARS5O67QMCVHTYAPTMM/ ======================== Updated packages in core/updates_testing: ======================== gdal-2.3.2-1.mga6 python2-gdal-2.3.2-1.mga6 python3-gdal-2.3.2-1.mga6 libgdal20-2.3.2-1.mga6 libgdal-devel-2.3.2-1.mga6 libgdal-static-devel-2.3.2-1.mga6 from gdal-2.3.2-1.mga6.src.rpm
Assignee: pkg-bugs => qa-bugs
Mageia 6, x86_64 Installed the core packages. python{2,3}-gdal packages were not available. They might be tools for scripting map-drawing commands. $ urpmq --whatrequires lib64gdal20 | sort -u gdal grass lib64gdal20 lib64gdal-devel lib64openscenegraph130 lib64postgis5 mapnik merkaartor mysql-workbench ncl postgis python-gdal qgis qgis-grass qlandkartegt qmapshack simgear Installed grass, which appears in the menus under Sciences as Grass70. This crashes on invocation. Run from the command-line it also fails to run. $ grass70 -gui Starting GRASS GIS... ERROR: <wxpython> requested, but not available. Run GRASS in text mode (-text) or install missing package (usually 'grass-gui'). Exiting... Package wxPython had been installed as a requirement. $ locate -i grass | grep gui shows a lot of files of this sort: /usr/lib64/grass70/gui/wxpython/wxplot/scatter.pyc So grass is no use for testing this. gdal has numerous man entries for separate functions, like gdal_sieve, and appears to be a graphical toolkit. The documentation on mapnik is extremely sparse. Not in the menus or accessible from the command-line. merkaartor looks more promising. It has a gui which can be launched from the command-line. Looks like it can create layered map projections. Had a go. Added a bending road to the worksheet, an isolated roundabout, a rectangular building and then converted the road into a bridge hundreds of kilometres long. Exercized the zoom function. Saved the "map" as untitled.mdc. That was all run under strace which showed that the gdal20 library was being used. $ grep gdal trace open("/lib64/libgdal.so.20", O_RDONLY|O_CLOEXEC) = 3 open("/usr/lib64/libgdal.so.20.0.2", O_RDONLY) = 3 open("/usr/lib64/libgdal.so.20.0.2", O_RDONLY) = 16 Shall run the updates tomorrow.
CC: (none) => tarazed25
If we stick to the script, it is gdal specifically which needs to be tested. $ urpmq --whatrequires gdal | sort -u gdal qgis qmapshack Updated the packages, including python2-gdal and python3-gdal. Installed qgis. Ran it with the filename of the crude map already generated by merkaartor in the hope that it would fit with qgis but it was ignored. An advanced interface appeared for managing Geographic Information Systems data. You would need a good tutorial to understand how to use it. It appears to be a drawing tool, file, database and project manager all in one and includes a web search facility. The help system points to API documentation at https://qgis.org/api/qgsquick.html which is aimed at mobile devices. The Gui comes up OK and poking it does no harm. Managed to raise a python console and typed some of the suggested help commands. The API link gives a link to a demo application repository:https://github.com/lutraconsulting/qgis-quick-demo-app with instructions for building it and assumes that Qt Creator is available. Altogether too ambitious for QA. Checked merkaartor by importing the initial crude effort at a map. There was a lot of graphical noise on the screen before it settled and displayed the untitled.mdc map. That is about as far as we can go with this. The software installs without trouble and applications dependent on gdal and libgdal at least launch with no obvious anomalies so it gets a 64-bit OK.
Whiteboard: (none) => MGA6-64-OK
Advisory from comment 4; no CVEs yet. Thanks Len for your habitual determined testing. Validating.
Keywords: (none) => advisory, validated_updateCC: (none) => lewyssmith, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2018-0451.html
Status: NEW => RESOLVEDResolution: (none) => FIXED