Bug 25791 - python-psutil new security issue CVE-2019-18874
Summary: python-psutil new security issue CVE-2019-18874
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-11-30 16:29 CET by David Walser
Modified: 2019-12-06 15:17 CET (History)
5 users (show)

See Also:
Source RPM: python-psutil-5.6.1-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2019-11-30 16:29:54 CET
Ubuntu has issued an advisory on November 28:
https://usn.ubuntu.com/4204-1/

Mageia 7 is also affected.
David Walser 2019-11-30 16:30:04 CET

Whiteboard: (none) => MGA7TOO

Comment 1 David GEIGER 2019-11-30 21:13:59 CET
Done!

CC: (none) => geiger.david68210

Comment 2 David Walser 2019-11-30 21:17:52 CET
Advisory:
========================

Updated python-psutil packages fix security vulnerability:

Riccardo Schirone discovered that psutil incorrectly handled certain reference
counting operations. An attacker could use this issue to cause psutil to crash,
resulting in a denial of service, or possibly execute arbitrary code
(CVE-2019-18874).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18874
https://usn.ubuntu.com/4204-1/
========================

Updated packages in core/updates_testing:
========================
python2-psutil-5.6.7-1.mga7
python3-psutil-5.6.7-1.mga7

from python-psutil-5.6.7-1.mga7.src.rpm

Whiteboard: MGA7TOO => (none)
Assignee: bugsquad => qa-bugs
Version: Cauldron => 7

Comment 3 Herman Viaene 2019-12-05 15:48:27 CET
MGA7-64 Plasma on Lenovo B50
No installation issues.
Used urpmq to find packages to test, picked terminator to test python2-psutil and glances for python3-psutil.
Used strace to check the usage, both programs seemed to perform well, and the trace shows references to the packages under test.
OK for me.

Whiteboard: (none) => MGA7-64-OK
CC: (none) => herman.viaene

Comment 4 Thomas Andrews 2019-12-05 21:46:20 CET
Validating. Advisory in Comment 2.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Thomas Backlund 2019-12-06 13:45:48 CET

CC: (none) => tmb
Keywords: (none) => advisory

Comment 5 Mageia Robot 2019-12-06 15:17:39 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2019-0370.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.