Bug 23827 - mkvtoolnix new security issue CVE-2018-4022
Summary: mkvtoolnix new security issue CVE-2018-4022
Status: RESOLVED WONTFIX
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: José Jorge
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-11-08 19:57 CET by David Walser
Modified: 2019-08-02 15:12 CEST (History)
0 users

See Also:
Source RPM: mkvtoolnix-9.7.1-1.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2018-11-08 19:57:25 CET
Fedora has issued an advisory today (November 8):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/E667ZUTXW46V6EUJTQQH5EQRFXF2EN4B/

The issue is fixed upstream in 28.2.0 (already in Cauldron).
Comment 1 David Walser 2018-11-20 23:22:02 CET
openSUSE has issued an advisory for this today (November 20):
https://lists.opensuse.org/opensuse-updates/2018-11/msg00096.html

They also included libmatroska in the update.
Comment 2 José Jorge 2018-11-21 15:41:50 CET
As the tool has changed a lot, I'd prefer not push the latest version to MGA6 as an update.
Comment 3 José Jorge 2019-08-02 15:12:51 CEST
Closing

Resolution: (none) => WONTFIX
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.