Bug 26259 - mbedtls new security issues fixed upstream in 2.16.5
Summary: mbedtls new security issues fixed upstream in 2.16.5
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-02-26 02:38 CET by David Walser
Modified: 2020-03-13 18:14 CET (History)
4 users (show)

See Also:
Source RPM: mbedtls-2.16.4-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-02-26 02:38:13 CET
Upstream has issued an advisory on February 20:
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2020-02

This issue and another are fixed upstream in 2.16.5:
https://tls.mbed.org/tech-updates/releases/mbedtls-2.16.5-and-2.7.14-released

Mageia 7 is also affected.
David Walser 2020-02-26 02:38:27 CET

Status comment: (none) => Fixed upstream in 2.16.5
Whiteboard: (none) => MGA7TOO

Rémi Verschelde 2020-02-26 08:40:54 CET

Status: NEW => ASSIGNED

Comment 1 Rémi Verschelde 2020-03-05 16:18:21 CET
Fixed in Cauldron with mbedtls-2.16.5-1.mga8.

Pushed mbedtls-2.16.5-1.mga7 to Mageia 7 core/updates_testing.

RPMs in core/updates_testing:
=============================

lib64mbedcrypto3-2.16.5-1.mga7
lib64mbedtls12-2.16.5-1.mga7
lib64mbedtls-devel-2.16.5-1.mga7
lib64mbedx509_0-2.16.5-1.mga7
mbedtls-2.16.5-1.mga7

SRPM in core/updates_testing:
=============================

mbedtls-2.16.5-1.mga7

Advisory pending.

Whiteboard: MGA7TOO => (none)
Assignee: rverschelde => qa-bugs
Version: Cauldron => 7

David Walser 2020-03-05 17:59:13 CET

Status comment: Fixed upstream in 2.16.5 => (none)

Comment 2 Len Lawrence 2020-03-05 20:58:13 CET
mga7, x86_64

Updated the packages, all of which were already installed at previous version.

Referred to previous test in https://bugs.mageia.org/show_bug.cgi?id=25952.
godot-3.1.1-1.mga7 already installed.

Launched godot and accessed "Templates", browsed a bit, then selected "2D Finite State Machine Demo", looked at the description, then downloaded the demo.  Entered the editor and selected AssetLib and browsed a few more projects, selected NotesTab, downloaded and installed that.

Hopefully that exercised mbedtls.  Forgot to run a trace.

The user's godot directory looks like this:
$ tree godot
godot
├── addons
│   └── notes_tab
│       ├── LICENSE
│       ├── notes_tab.gd
│       ├── notes_tab.tscn
......
├── project.godot
└── state_machine
    ├── state.gd
    └── state_machine.gd

14 directories, 43 files

Giving this an OK for 64-bits.

CC: (none) => tarazed25
Whiteboard: (none) => MGA7-64-OK

Thomas Backlund 2020-03-06 23:19:31 CET

CC: (none) => tmb
Keywords: (none) => advisory

Comment 3 Thomas Andrews 2020-03-08 21:46:50 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 4 Mageia Robot 2020-03-08 23:38:56 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0130.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED

Comment 5 Rémi Verschelde 2020-03-09 09:00:30 CET
Thanks for writing the advisory Thomas :)
Comment 6 David Walser 2020-03-13 18:14:12 CET
Fedora has issued an advisory for this on March 12:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/2U5SD5ORL6H6YYMFTMQNOIGNNXVYVCAM/

Note You need to log in before you can comment on or make changes to this bug.