Bug 25763 - python-sqlalchemy new security issues CVE-2019-7164 and CVE-2019-7548
Summary: python-sqlalchemy new security issues CVE-2019-7164 and CVE-2019-7548
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-11-26 21:33 CET by David Walser
Modified: 2019-11-30 14:08 CET (History)
6 users (show)

See Also:
Source RPM: python-sqlalchemy-1.2.12-2.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2019-11-26 21:33:19 CET
openSUSE has issued an advisory on September 1:
https://lists.opensuse.org/opensuse-updates/2019-08/msg00221.html
David Walser 2019-11-26 21:33:32 CET

CC: (none) => geiger.david68210, jani.valimaa

David Walser 2019-11-26 21:33:46 CET

Summary: python-sqlalchemy new security issues => python-sqlalchemy new security issues CVE-2019-7164 and CVE-2019-7548

Comment 1 Lewis Smith 2019-11-26 21:56:58 CET
Assigning to philippem as the relevant registered maintainer.

Assignee: bugsquad => makowski.mageia

Comment 2 David Walser 2019-11-26 22:34:35 CET
I thought he left Mageia.
Comment 3 David GEIGER 2019-11-27 14:35:09 CET
Done updating to latest 1.2.19 release from 1.2.x branch and adding a debian patch!
Comment 4 David Walser 2019-11-27 18:35:01 CET
Advisory:
========================

Updated python-sqlalchemy packages fix security vulnerabilities:

SQL Injection via the order_by parameter (CVE-2019-7164).

SQL Injection via the group_by parameter (CVE-2019-7548).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7164
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7548
https://lists.opensuse.org/opensuse-updates/2019-08/msg00221.html
========================

Updated packages in core/updates_testing:
========================
python2-sqlalchemy-1.2.19-1.mga7
python3-sqlalchemy-1.2.19-1.mga7

from python-sqlalchemy-1.2.19-1.mga7.src.rpm

Assignee: makowski.mageia => qa-bugs

Comment 5 Herman Viaene 2019-11-28 11:28:05 CET
MGA7-64 Plasma on Lenovo B50
No installation issues
Ref to bug 1738 Comment 5 for testing,(gourmet appears in the required list forpython2-sqlalchemy)   so installed gourmet and imported recipe
$ gourmet
Gtk-Message: 10:59:02.350: Failed to load module "canberra-gtk-module"
No gst player
No windows player
CONTENT TYPE =  text/html; charset=UTF-8
emit ('completed',)
emit ('done',)
Doing import of http://www.canadianwineguy.com/2007/08/07/chili-recipe/ <web_import_plugin.generic_web_importer_plugin.GenericWebImporter instance at 0x7f89bc4370a0>
HERE's the data we got: <!DOCTYPE html>
<html lang="en-US">
and a lot more feedback as operations progressed.
Created a shopping list, tried out the units converter, but couldn't get this one to change the units in a shopping list or a displayed recipe, but that is probably just me...
Used anki to test python3-sqlalchemy, also works OK.

Whiteboard: (none) => MGA7-64-OK
CC: (none) => herman.viaene

Comment 6 Thomas Andrews 2019-11-29 01:00:55 CET
(In reply to Herman Viaene from comment #5)

> Used anki to test python3-sqlalchemy, also works OK.

Herman, did you use anki before or after updating the glib packages in Bug 25276? 

If after, I believe it should count as a test of those packages too, and enough verification to give that bug an OK and send it on its way. See Bug 25525 for further information.

CC: (none) => andrewsfarm

Comment 7 Thomas Andrews 2019-11-29 01:14:23 CET
Since this is listed as a critical update, I'm sending it along rather than wait for the answer to the question I posed in Comment 6. Herman, if you could try anki as part of a test for Bug 25276, I'd appreciate it.

Validating. Advisory in Comment 4.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Thomas Backlund 2019-11-30 11:17:23 CET

Keywords: (none) => advisory
CC: (none) => tmb

Comment 8 Mageia Robot 2019-11-30 14:08:00 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2019-0350.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.