Bug 25751 - libqb new security issue CVE-2019-12779
Summary: libqb new security issue CVE-2019-12779
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-11-26 15:00 CET by David Walser
Modified: 2020-01-28 08:54 CET (History)
4 users (show)

See Also:
Source RPM: libqb-0.16.0-6.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2019-11-26 15:00:06 CET
openSUSE has issued an advisory on July 20:
https://lists.opensuse.org/opensuse-updates/2019-07/msg00083.html

The issue is fixed upstream in 1.0.5.

Mageia 7 is also affected.
David Walser 2019-11-26 15:00:15 CET

Whiteboard: (none) => MGA7TOO

Comment 1 Lewis Smith 2019-11-26 21:29:47 CET
libqb has no maintainer, so assigning this globally.

Assignee: bugsquad => pkg-bugs

David Walser 2020-01-14 17:44:33 CET

Status comment: (none) => Fixed upstream in 1.0.5

Comment 2 David Walser 2020-01-23 13:23:16 CET
libqb-1.0.5-1.mga8 uploaded for Cauldron by David Geiger.

CC: (none) => geiger.david68210
Version: Cauldron => 7
Whiteboard: MGA7TOO => (none)

Comment 3 David Walser 2020-01-23 17:02:51 CET
Updated package uploaded for Mageia 7 by David Geiger.

Advisory:
========================

Updated libqb packages fix security vulnerability:

Insecure treatment of IPC temporary files which could allow a local attacker to
overwrite privileged system files (CVE-2019-12779).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12779
https://lists.opensuse.org/opensuse-updates/2019-07/msg00083.html
========================

Updated packages in core/updates_testing:
========================
libqb0-1.0.5-1.mga7
libqb-devel-1.0.5-1.mga7

from libqb-1.0.5-1.mga7.src.rpm

Assignee: pkg-bugs => qa-bugs
Status comment: Fixed upstream in 1.0.5 => (none)

Comment 4 Len Lawrence 2020-01-23 20:41:27 CET
Mageia7, x86_64

This looks quite difficult to set up.  It is a development environment apparently which requires certain files to copied from source to /etc/corosync.  There is no config file provided out of the box, not even a template so this may take a while to figure out.  It is highly probable that this shall result in "failure to launch", in which case it goes back on the conveyor belt.

CC: (none) => tarazed25

Comment 5 Len Lawrence 2020-01-23 20:43:39 CET
Oops, I missed out the the basics.  libqp0 is used by corosync and pacemaker, neither of which are familiar, hence my scepticism.
Comment 6 Len Lawrence 2020-01-25 00:22:35 CET
As agreed at the last QA meeting this should be passed on the basis of a clean update.

Whiteboard: (none) => MGA7-64-OK

Comment 7 Thomas Andrews 2020-01-27 18:30:30 CET
Validating. Advisory in Comment 3.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Lewis Smith 2020-01-27 19:27:21 CET

Keywords: (none) => advisory

Comment 8 Mageia Robot 2020-01-28 08:54:16 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0048.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.