Bug 25932 - filezilla/libfilezilla security update
Summary: filezilla/libfilezilla security update
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on: 25760
Blocks:
  Show dependency treegraph
 
Reported: 2019-12-23 19:08 CET by David Walser
Modified: 2019-12-31 17:52 CET (History)
5 users (show)

See Also:
Source RPM: filezilla-3.42.1-1.mga7.src.rpm, libfilezilla-0.16.0-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2019-12-23 19:08:25 CET
Fedora has issued advisories on July 6:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DYM7BZFULYL5BCP2SHUMLBOW2W6CDWPX/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/LPQ3OUS2C3NIXCARPY7ELMMGKDQZXFUH/

They update to newer versions of filezilla/libfilezilla than we have, fixing a security issue.  More recently, upstream released on December 20 libfilezilla 0.19.3 and filezilla 3.46.1, updating the bundled PuTTY (also fixing security issues), and today (December 23) filezilla 3.46.3, fixing more bugs:
https://filezilla-project.org/
Comment 1 David Walser 2019-12-24 00:37:03 CET
Packages uploaded by David Geiger:
libfilezilla3-0.19.3-1.mga7
libfilezilla-devel-0.19.3-1.mga7
libfilezilla-i18n-0.19.3-1.mga7
filezilla-3.46.3-1.mga7

from SRPMS:
libfilezilla-0.19.3-1.mga7.src.rpm
filezilla-3.46.3-1.mga7.src.rpm

Advisory to come later.

Assignee: geiger.david68210 => qa-bugs
CC: (none) => geiger.david68210

Comment 2 PC LX 2019-12-24 12:59:18 CET
Installed and tested without issues.


Tested on various (S)FTP servers and sites. All worked.


System: Mageia 7, x86_64, Plasma DE, LXQt DE, Intel CPU, nVidia GPU using nvidia340 proprietary  driver.


$ uname -a
Linux marte 5.4.6-desktop-1.mga7 #1 SMP Sun Dec 22 09:44:20 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
$ rpm -qa | grep filezilla
filezilla-3.46.3-1.mga7
libfilezilla-i18n-0.19.3-1.mga7
lib64filezilla3-0.19.3-1.mga7

Whiteboard: (none) => MGA7-64-OK
CC: (none) => mageia

Comment 3 Thomas Andrews 2019-12-26 22:36:45 CET
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

David Walser 2019-12-27 02:34:51 CET

Depends on: (none) => 25760

Thomas Backlund 2019-12-31 16:49:24 CET

Keywords: (none) => advisory
CC: (none) => tmb

Comment 4 Mageia Robot 2019-12-31 17:52:41 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2019-0417.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.