Bug 24182 - php-pear-Archive_Tar new security issue CVE-2018-1000888
Summary: php-pear-Archive_Tar new security issue CVE-2018-1000888
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Marc Krämer
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-01-14 20:34 CET by David Walser
Modified: 2019-01-15 14:02 CET (History)
2 users (show)

See Also:
Source RPM: php-pear-Archive_Tar-1.4.3-2.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2019-01-14 20:34:41 CET
Ubuntu has issued an advisory today (January 14):
https://usn.ubuntu.com/3857-1/

The issue is fixed upstream in 1.4.4 (with a regression fix in 1.4.5).

Mageia 6 is also affected.
David Walser 2019-01-14 20:34:49 CET

Whiteboard: (none) => MGA6TOO

Comment 1 Marja Van Waes 2019-01-15 08:26:33 CET
Assigning to the PHP stack maintainers.

Assignee: bugsquad => php
CC: (none) => marja11

Comment 2 Marc Krämer 2019-01-15 10:49:19 CET
If I don't miss anything we don't have this package in mga6.

Updated cauldron.

CC: (none) => mageia

Marc Krämer 2019-01-15 10:49:27 CET

Assignee: php => mageia

Comment 3 David Walser 2019-01-15 13:24:07 CET
Ahh indeed.  Thanks.

Fixed in php-pear-Archive_Tar-1.4.5-1.mga7.

Status: NEW => RESOLVED
Whiteboard: MGA6TOO => (none)
Resolution: (none) => FIXED

Comment 4 Marc Krämer 2019-01-15 14:02:19 CET
you are doing a good job, I was just wondering if I was wrong :)

Note You need to log in before you can comment on or make changes to this bug.