Bug 26689 - libvpx new security issue CVE-2020-0034
Summary: libvpx new security issue CVE-2020-0034
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact: Sec team
URL:
Whiteboard: MGA7TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2020-05-26 23:54 CEST by David Walser
Modified: 2020-05-27 15:26 CEST (History)
1 user (show)

See Also:
Source RPM: libvpx-1.8.2-2.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-05-26 23:54:12 CEST
openSUSE has issued an advisory on May 23:
https://lists.opensuse.org/opensuse-updates/2020-05/msg00126.html

Mageia 7 is also affected.
David Walser 2020-05-26 23:54:26 CEST

Whiteboard: (none) => MGA7TOO

Comment 1 David GEIGER 2020-05-27 15:19:34 CEST
This security issue don't affect release 1.8.1 and 1.8.2, already fixed upstream.

CC: (none) => geiger.david68210

Comment 2 David Walser 2020-05-27 15:26:56 CEST
Indeed, fixed upstream in 1.7.0 it looks like.

Resolution: (none) => INVALID
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.