openSUSE has issued an advisory on April 12: https://lists.opensuse.org/opensuse-updates/2019-04/msg00113.html Mageia 6 is also affected.
Whiteboard: (none) => MGA6TOO
Assigning to all packagers collectively, since there is no registered maintainer for this package. Also CC'ing some submitters.
Assignee: bugsquad => pkg-bugsCC: (none) => cjw, geiger.david68210, marja11, mrambo, smelror
Already fixed in current 10.86.02 release from Cauldron!
mga6 fixed!
Advisory: ======================== Updated netpbm packages fix security vulnerability: The pm_mallocarray2 function allowed remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file (CVE-2018-8975). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8975 https://lists.opensuse.org/opensuse-updates/2019-04/msg00113.html ======================== Updated packages in core/updates_testing: ======================== netpbm-10.73.07-1.1.mga6 libnetpbm11-10.73.07-1.1.mga6 libnetpbm-devel-10.73.07-1.1.mga6 from netpbm-10.73.07-1.1.mga6.src.rpm
Whiteboard: MGA6TOO => (none)Source RPM: netpbm-10.86.02-1.mga7.src.rpm => netpbm-10.73.07-1.mga6.src.rpmAssignee: pkg-bugs => qa-bugsVersion: Cauldron => 6
MGA6-32 MATE on IBM Thinkpad R50e No installation issues. Ref bug 20245 for testing, created small ppm file by drawing and exporting from xfig (posting as attachment) At CLI: $ ppmtojpeg testppm.ppm > testppm.jpg $ ppmtobmp testppm.ppm > testppm.bmp ppmtobmp: analyzing colors... ppmtobmp: 2 colors found ppmtobmp: Writing 1 bits per pixel with a color palette Both jpg and bmp files display correctly in ristretto.
CC: (none) => herman.viaeneWhiteboard: (none) => MGA6-32-OK
<Some ugly words> even this simple drawing is too large: 1.6 Mb.
Advisory committed to svn. Validating the update.
Keywords: (none) => advisory, validated_updateCC: (none) => davidwhodgins, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2019-0183.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED