Bug 26031 - e2fsprogs new security issue CVE-2019-5188
Summary: e2fsprogs new security issue CVE-2019-5188
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-01-08 01:21 CET by David Walser
Modified: 2020-01-17 11:18 CET (History)
4 users (show)

See Also:
Source RPM: e2fsprogs-1.45.4-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-01-08 01:21:24 CET
e2fsprogs 1.54.5 has been released today (January 7), fixing at least one security issue:
http://e2fsprogs.sourceforge.net/e2fsprogs-release.html#1.45.5
Comment 1 Lewis Smith 2020-01-08 10:17:33 CET
Assigning to tv as the active maintainer of this pkg.

Assignee: bugsquad => thierry.vignaud

Comment 2 David Walser 2020-01-13 23:46:06 CET
SUSE has issued an advisory for this today (January 13):
http://lists.suse.com/pipermail/sle-security-updates/2020-January/006332.html
Comment 3 Thierry Vignaud 2020-01-14 12:32:04 CET
Advisory:
=========
e2fsprogs was updated to 1.45.5 in order to fix several bugs, including a potential security issues (CVE-2019-5188).
See http://e2fsprogs.sourceforge.net/e2fsprogs-release.html#1.45.5 for details

Assignee: thierry.vignaud => qa-bugs
Status: NEW => ASSIGNED
Source RPM: e2fsprogs-1.45.4-1.mga7.src.rpm => e2fsprogs-1.45.5-1.mga7

Comment 4 David Walser 2020-01-14 14:12:17 CET
e2fsprogs-1.45.5-1.mga7
libext2fs2-1.45.5-1.mga7
libext2fs-devel-1.45.5-1.mga7

from e2fsprogs-1.45.5-1.mga7.src.rpm

Source RPM: e2fsprogs-1.45.5-1.mga7 => e2fsprogs-1.45.4-1.mga7.src.rpm

Comment 5 Herman Viaene 2020-01-15 15:44:56 CET
MGA7-64 Plasma on Lenovo B50
No installation issues.
Ref to bugs 15208 and 15352 for tests.
Ran all commands as root to avoid having to jump around in the file system (not shown in the procedure).
All output seems sensible.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA7-64-OK

Comment 6 Thomas Andrews 2020-01-16 19:35:16 CET
Validating. Advisory in Comment 3.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Thomas Backlund 2020-01-17 10:45:29 CET

Keywords: (none) => advisory
CC: (none) => tmb

Comment 7 Mageia Robot 2020-01-17 11:18:04 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0039.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.