Bug 25971 - librabbitmq new security issue CVE-2019-18609
Summary: librabbitmq new security issue CVE-2019-18609
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Nicolas Lécureuil
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-12-27 04:57 CET by David Walser
Modified: 2021-07-01 18:20 CEST (History)
2 users (show)

See Also:
Source RPM: librabbitmq-0.8.0-5.mga7.src.rpm
CVE:
Status comment: Fixed upstream in 0.10.0


Attachments

Description David Walser 2019-12-27 04:57:24 CET
Debian-LTS and Ubuntu have issued advisories on December 5, 6, and 11:
https://www.debian.org/lts/security/2019/dla-2022
https://usn.ubuntu.com/4214-1/
https://usn.ubuntu.com/4214-2/

Mageia 7 is also affected.
David Walser 2019-12-27 04:57:47 CET

Whiteboard: (none) => MGA7TOO
See Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=25970

Comment 1 David Walser 2019-12-27 05:07:39 CET
Fedora has issued an advisory for this on December 10:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/XQER6XTKYMHNQR7QTHW7DJAH645WQROU/

The issue is fixed upstream in 0.10.0.
David Walser 2020-01-14 17:36:39 CET

Status comment: (none) => Fixed upstream in 0.10.0

Comment 2 Nicolas Lécureuil 2020-05-29 01:41:23 CEST
https://github.com/alanxz/rabbitmq-c/commit/fc85be7123050b91b054e45b91c78d3241a5047a

patch added in cauldron and mga7 updates_testing:

librabbitmq-0.8.0-5.1.mga7

Assignee: mageia => qa-bugs
Whiteboard: MGA7TOO => (none)
Status comment: Fixed upstream in 0.10.0 => (none)
Version: Cauldron => 7

Nicolas Lécureuil 2020-05-29 02:17:20 CEST

CC: (none) => mageia
Assignee: qa-bugs => mageia

David Walser 2020-05-29 02:41:44 CEST

Status comment: (none) => Fixed upstream in 0.10.0
Whiteboard: (none) => MGA7TOO
Version: 7 => Cauldron

Comment 3 David Walser 2020-09-01 00:08:14 CEST
librabbitmq-0.10.0-1.mga8 uploaded for Cauldron by Guillaume.

CC: (none) => guillomovitch
Version: Cauldron => 7
Whiteboard: MGA7TOO => (none)

Comment 4 David Walser 2020-10-13 16:31:36 CEST
RedHat has issued an advisory for this on September 29:
https://access.redhat.com/errata/RHSA-2020:3949
Comment 5 David Walser 2020-11-05 22:30:12 CET
RedHat has issued an advisory for this on November 3:
https://access.redhat.com/errata/RHSA-2020:4445
Comment 6 David Walser 2021-07-01 18:20:56 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Status: NEW => RESOLVED
Resolution: (none) => OLD


Note You need to log in before you can comment on or make changes to this bug.