Bug 25684 - libvorbis new security issues CVE-2018-1039[23]
Summary: libvorbis new security issues CVE-2018-1039[23]
Status: RESOLVED DUPLICATE of bug 23145
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard: MGA7TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2019-11-12 20:38 CET by David Walser
Modified: 2019-11-12 23:03 CET (History)
1 user (show)

See Also:
Source RPM: libvorbis-1.3.6-3.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2019-11-12 20:38:46 CET
RedHat has issued an advisory on November 5:
https://access.redhat.com/errata/RHSA-2019:3703

Mageia 7 is also affected.
David Walser 2019-11-12 20:38:54 CET

Whiteboard: (none) => MGA7TOO

Comment 1 Lewis Smith 2019-11-12 21:11:49 CET
Assigning this globally as libvorbis has no registered maintainer.

Assignee: bugsquad => pkg-bugs

Comment 2 David GEIGER 2019-11-12 21:40:33 CET
Seems that CVE-2018-10392 and CVE-2018-10393 were already fixed in libvorbis-1.3.6-3.mga7.src.rpm:

http://svnweb.mageia.org/packages?view=revision&revision=1238085

CC: (none) => geiger.david68210

Comment 3 David Walser 2019-11-12 23:03:03 CET
I wonder why that didn't turn up in my Bugzilla search.

*** This bug has been marked as a duplicate of bug 23145 ***

Status: NEW => RESOLVED
Resolution: (none) => DUPLICATE


Note You need to log in before you can comment on or make changes to this bug.