Bug 24900 - bzip2 new security issue CVE-2019-12900
Summary: bzip2 new security issue CVE-2019-12900
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-06-04 13:11 CEST by David Walser
Modified: 2019-11-30 14:07 CET (History)
7 users (show)

See Also:
Source RPM: bzip2-1.0.6-13.mga7.src.rpm
CVE: CVE-2019-12900
Status comment: Fixed upstream in 1.0.7


Attachments

Description David Walser 2019-06-04 13:11:14 CEST
Some bugs (and patches to fix them) have been announced for bzip2:
https://www.openwall.com/lists/oss-security/2019/06/03/3
https://www.openwall.com/lists/oss-security/2019/06/04/3
David Walser 2019-06-04 13:11:25 CEST

Whiteboard: (none) => MGA7TOO, MGA6TOO

Comment 1 Marja Van Waes 2019-06-05 18:30:06 CEST
Assigning to the base system maintainers, CC'ing the registered maintainer.

CC: (none) => marja11, tmb
Assignee: bugsquad => basesystem

Comment 2 David Walser 2019-06-28 22:18:52 CEST
bzip2 1.0.7 has been released on June 27, and CVEs have been allocated for two of the fixes:
https://sourceware.org/ml/bzip2-devel/2019-q2/msg00022.html

Status comment: (none) => Fixed upstream in 1.0.7
Summary: Crasher bugs in bzip2 => bzip2 new security issues CVE-2016-3189 and CVE-2019-12900

Comment 3 David Walser 2019-06-28 22:30:18 CEST
Note that there are regressions and issues with the fixes and further discussion about it.  It sounds like a 1.0.8 release may be forthcoming soon.
Comment 4 David Walser 2019-07-15 13:07:05 CEST
bzip2 1.0.8 has been released on July 13 and should be a safe update:
https://sourceware.org/ml/bzip2-devel/2019-q3/msg00031.html
Comment 5 David Walser 2019-07-17 13:05:01 CEST
David updated Cauldron to 1.0.8.

Whiteboard: MGA7TOO, MGA6TOO => MGA6TOO
CC: (none) => geiger.david68210
Version: Cauldron => 7

Comment 6 David Walser 2019-08-11 23:13:46 CEST
We may have addressed CVE-2016-3189 in Bug 18742.

Regardless, Ubuntu has issued an advisory for this on June 26:
https://usn.ubuntu.com/4038-1/

Severity: normal => major

Comment 7 David Walser 2019-11-26 16:43:10 CET
openSUSE has issued an advisory for this on July 21:
https://lists.opensuse.org/opensuse-updates/2019-07/msg00106.html
Comment 8 Nicolas Salguero 2019-11-27 14:09:56 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors. (CVE-2019-12900)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12900
https://www.openwall.com/lists/oss-security/2019/06/03/3
https://www.openwall.com/lists/oss-security/2019/06/04/3
https://sourceware.org/ml/bzip2-devel/2019-q2/msg00022.html
https://sourceware.org/ml/bzip2-devel/2019-q3/msg00031.html
https://usn.ubuntu.com/4038-1/
https://lists.opensuse.org/opensuse-updates/2019-07/msg00106.html
========================

Updated packages in core/updates_testing:
========================
bzip2-1.0.8-1.mga7
lib(64)bz2_1-1.0.8-1.mga7
lib(64)bz2-devel-1.0.8-1.mga7

from SRPMS:
bzip2-1.0.8-1.mga7.src.rpm

Whiteboard: MGA6TOO => (none)
CC: (none) => nicolas.salguero
Source RPM: bzip2-1.0.6-12.mga7.src.rpm => bzip2-1.0.6-13.mga7.src.rpm
CVE: (none) => CVE-2019-12900
Assignee: basesystem => qa-bugs
Status: NEW => ASSIGNED
Summary: bzip2 new security issues CVE-2016-3189 and CVE-2019-12900 => bzip2 new security issue CVE-2019-12900

Comment 9 Herman Viaene 2019-11-28 11:47:21 CET
MGA7-64 Plasma on Lenovo B50
No installation issues.
Copied some pictures to separate folder:1 jpegg, 1 tif and 4 ORF files (Olympus RAW format), together 102Mb
Then
$ bzip2 *
produces
$ ls
ikke2012.jpg.bz2  P7212389.ORF.bz2  P7212390.ORF.bz2  P7212391.ORF.bz2  P7212392.ORF.bz2  p.tif.bz2
size together 71Mb
then
$ bunzip2 *
$ ls
ikke2012.jpg  P7212389.ORF  P7212390.ORF  P7212391.ORF  P7212392.ORF  p.tif
pictures display OK and again 102Mb in total
Update OK for me.

Whiteboard: (none) => MGA7-64-OK
CC: (none) => herman.viaene

Comment 10 Thomas Andrews 2019-11-29 01:05:17 CET
Validating. Advisory in Comment 8.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Thomas Backlund 2019-11-30 11:27:55 CET

Keywords: (none) => advisory

Comment 11 Mageia Robot 2019-11-30 14:07:35 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2019-0338.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.