https://linuxsecurity.com/advisories/deblts/debian-lts-dla-2005-1-tnef-security-update-15-19-18
CVE: (none) => CVE-2019-18849
Thank you for this notice. I have checked for no duplicate bug. Assigning to DavidG as latest committer; CC Stig as having done it before. No registered maintainer.
Assignee: bugsquad => geiger.david68210Source RPM: tnef => tnef-1.4.17-2.mga7.src.rpmCC: (none) => smelror
Done for mga7!
Saving advisory for the moment...David, it needs to be updated in Cauldron also. Advisory: ======================== Updated tnef package fixes security vulnerability: In tnef, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup (CVE-2019-18849). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18849 https://www.debian.org/lts/security/2019/dla-2005 ======================== Updated packages in core/updates_testing: ======================== tnef-1.4.18-1.mga7 from tnef-1.4.18-1.mga7.src.rpm
Summary: tnef security update CVE-2019-18849 => tnef new security issue CVE-2019-18849Version: 7 => CauldronSeverity: normal => majorWhiteboard: (none) => MGA7TOO
Already updated in Cauldron!
Yes I see. Sophie is outdated. QA, advisory and package in Comment 3.
Whiteboard: MGA7TOO => (none)Version: Cauldron => 7CC: (none) => geiger.david68210Assignee: geiger.david68210 => qa-bugs
MGA7-64 Plasma on Lenovo B50 No installation issues. Ref to bug 20343 for a testfile, then at CLI $ tnef -v winmail.dat zappa_av1.jpg | zappa_av1.jpg | unknown | bookmark.htm | bookmark.htm | unknown | The Picture shows OK and I could import the bookmarks into Firefox OK for me
CC: (none) => herman.viaeneWhiteboard: (none) => MGA7-64-OK
Validating.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => advisoryCC: (none) => tmb
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2019-0367.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED