Bug 26523 - openssl new security issue CVE-2020-1967
Summary: openssl new security issue CVE-2020-1967
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-04-21 22:19 CEST by David Walser
Modified: 2020-04-22 16:00 CEST (History)
2 users (show)

See Also:
Source RPM: openssl-1.1.1f-1.mga8.src.rpm
CVE:
Status comment: Fixed upstream in 1.1.1g


Attachments

Description David Walser 2020-04-21 22:19:26 CEST
OpenSSL has issued an advisory today (April 21):
https://www.openssl.org/news/secadv/20200421.txt

The issue is fixed upstream in 1.1.1g.

1.0.2 and 1.1.0 are not affect, thus neither is Mageia 7.
David Walser 2020-04-21 22:19:40 CEST

Status comment: (none) => Fixed upstream in 1.1.1g

Comment 1 r howard 2020-04-22 02:08:52 CEST
With regards to 1.0.2 and 1.1.0 are not affect, thus neither is Mageia 7. That may or may not be true as OpenSSL 1.0.2 and 1.1.0 are no longer supported by the OpenSSL project.
From https://www.openssl.org/policies/releasestrat.html :
Version 1.0.2 is no longer supported. Extended support for 1.0.2 to gain access to security fixes for that version is available.
Versions 1.1.0, 1.0.1, 1.0.0 and 0.9.8 are no longer supported.

CC: (none) => rihoward1

Comment 2 David Walser 2020-04-22 02:11:46 CEST
The advisory explicitly stated that older branches are not affected.
Comment 3 r howard 2020-04-22 02:37:58 CEST
David my apologies.  I was super busy and only read the first line of the advisory. I should of read more.

I guess I should ask the question in the email listif OpenSSL 1.1.1g should be back ported to Mageia 7
Comment 4 David Walser 2020-04-22 02:41:49 CEST
Ideally it would be (I filed Bug 24433 for that a long time ago), but it's not as simple as backporting the newer openssl itself, but we would also have to backport updates and/or patches for all of the packages using it, to be compatible with the API changes, and that hasn't even completely happened in Cauldron yet.
Comment 5 r howard 2020-04-22 02:48:56 CEST
Yes that sounds like a reasonable limitation due to shortage of packagers.
Comment 6 Nicolas Salguero 2020-04-22 15:55:23 CEST
Hi,

This is done: openssl-1.1.1g-1.mga8.

Best regards,

Nico.

CC: (none) => nicolas.salguero

Comment 7 David Walser 2020-04-22 16:00:59 CEST
Thanks!

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.