Bug 26588 - libslirp/slirp4netns new security issue CVE-2020-1983
Summary: libslirp/slirp4netns new security issue CVE-2020-1983
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Joseph Wang
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-05-04 20:28 CEST by David Walser
Modified: 2020-05-12 15:41 CEST (History)
1 user (show)

See Also:
Source RPM: libslirp-4.2.0-1.mga8.src.rpm, slirp4netns-0.4.4-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Comment 1 David GEIGER 2020-05-05 10:37:13 CEST
Done for Cauldron!

CC: (none) => geiger.david68210

Comment 2 David Walser 2020-05-05 16:03:38 CEST
Fixed in libslirp-4.2.0-2.mga8.

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 3 David Walser 2020-05-06 20:38:59 CEST
SUSE has issued an advisory toay (May 6):
http://lists.suse.com/pipermail/sle-security-updates/2020-May/006785.html

The slirp4netns package is also affected.

I'm not sure if they just upgraded to 0.4.5 or if it needed to be patched.

Status: RESOLVED => REOPENED
Source RPM: libslirp-4.2.0-1.mga8.src.rpm => libslirp-4.2.0-1.mga8.src.rpm, slirp4netns-0.4.4-1.mga8.src.rpm
Assignee: thierry.vignaud => joequant
Resolution: FIXED => (none)
Summary: libslirp new security issue CVE-2020-1983 => libslirp/slirp4netns new security issue CVE-2020-1983

Comment 4 David Walser 2020-05-11 22:48:42 CEST
(In reply to David Walser from comment #3)
> SUSE has issued an advisory today (May 6):
> http://lists.suse.com/pipermail/sle-security-updates/2020-May/006785.html
> 
> The slirp4netns package is also affected.
> 
> I'm not sure if they just upgraded to 0.4.5 or if it needed to be patched.

openSUSE has issued an advisory for this today (May 11):
https://lists.opensuse.org/opensuse-updates/2020-05/msg00065.html

They only needed to update to 0.4.5.
Comment 5 David GEIGER 2020-05-12 07:35:23 CEST
Latest release 1.0.1 uses now system libslirp.
Comment 6 David Walser 2020-05-12 14:30:53 CEST
OK, that's good.  It hasn't been pushed yet.
Comment 7 David GEIGER 2020-05-12 15:34:42 CEST
So fixed for Cauldron updating slirp4netns to latest 1.0.1 release that uses now system libslirp.
Comment 8 David Walser 2020-05-12 15:41:05 CEST
Fixed in slirp4netns-1.0.1-1.mga8.  Thanks!

Resolution: (none) => FIXED
Status: REOPENED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.