Bug 24355 - flatpak new security issue related to CVE-2019-5736 (CVE-2019-8308) and new security issue CVE-2019-10063
Summary: flatpak new security issue related to CVE-2019-5736 (CVE-2019-8308) and new s...
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: Neal Gompa
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: 23866
  Show dependency treegraph
 
Reported: 2019-02-13 04:10 CET by David Walser
Modified: 2019-11-26 21:39 CET (History)
2 users (show)

See Also:
Source RPM: flatpak-1.0.6-1.mga7.src.rpm
CVE:
Status comment: Fixed upstream in 1.0.8 and 1.2.4


Attachments

Description David Walser 2019-02-13 04:10:50 CET
Fedora has issued an advisory tomorrow (February 13):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/KEEWWTWPOXFOQSOBEEMYNYIRW5I3RTWB/

The issue is fixed upstream in 1.2.3.

The RedHat bug has a link to the upstream commit that fixed the issue.

Mageia 6 is also affected.
David Walser 2019-02-13 04:11:07 CET

CC: (none) => shlomif
Blocks: (none) => 23866
Whiteboard: (none) => MGA6TOO

Comment 1 David Walser 2019-02-15 00:44:44 CET
Debian has issued an advisory for this on February 12:
https://www.debian.org/security/2019/dsa-4390

According to the Debian bug, it's also fixed upstream in 1.0.7.

Status comment: (none) => Fixed upstream in 1.0.7 and 1.2.3

Comment 2 David Walser 2019-02-15 20:59:47 CET
flatpak-1.0.7-1.mga7 uploaded for Cauldron by Shlomi.

Version: Cauldron => 6
Whiteboard: MGA6TOO => (none)

Comment 3 David Walser 2019-05-08 13:34:56 CEST
RedHat has issued an advisory on May 7:
https://access.redhat.com/errata/RHSA-2019:1024

The issue is fixed upstream in 1.0.8 and 1.2.4.

Summary: flatpak new security issue related to CVE-2019-5736 => flatpak new security issue related to CVE-2019-5736 and new security issue CVE-2019-10063
Status comment: Fixed upstream in 1.0.7 and 1.2.3 => Fixed upstream in 1.0.8 and 1.2.4

Comment 4 Morgan Leijström 2019-11-06 17:38:56 CET
Mageia 6 is EOL

Mageia 7 have Flatpak 1.4.1, with request for upgrade in Bug 25463

Resolution: (none) => OLD
CC: (none) => fri
Status: NEW => RESOLVED

Comment 5 David Walser 2019-11-26 21:39:08 CET
Apparently the first issue got CVE-2019-8308:
https://lists.opensuse.org/opensuse-updates/2019-08/msg00222.html

Summary: flatpak new security issue related to CVE-2019-5736 and new security issue CVE-2019-10063 => flatpak new security issue related to CVE-2019-5736 (CVE-2019-8308) and new security issue CVE-2019-10063


Note You need to log in before you can comment on or make changes to this bug.