Bug 24512 - libcomps new security issue CVE-2019-3817
Summary: libcomps new security issue CVE-2019-3817
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Neal Gompa
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-03-13 20:07 CET by David Walser
Modified: 2019-11-12 18:11 CET (History)
0 users

See Also:
Source RPM: libcomps-0.1.9-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2019-03-13 20:07:12 CET
openSUSE has issued an advisory on March 11:
https://lists.opensuse.org/opensuse-updates/2019-03/msg00054.html

Mageia 6 is also affected.
David Walser 2019-03-13 20:07:17 CET

Whiteboard: (none) => MGA6TOO

David Walser 2019-06-23 19:19:57 CEST

Whiteboard: MGA6TOO => MGA7TOO, MGA6TOO

Comment 1 David Walser 2019-11-12 18:11:13 CET
RedHat has issued an advisory for this on November 5:
https://access.redhat.com/errata/RHSA-2019:3583

The issue is fixed upstream in 0.1.10.

We shipped Mageia 7 with 0.1.11, and Mageia 6 is EOL.

Whiteboard: MGA7TOO, MGA6TOO => (none)
Status: NEW => RESOLVED
Resolution: (none) => OLD
Version: Cauldron => 6


Note You need to log in before you can comment on or make changes to this bug.