Bug 27492 - lout new security issues CVE-2019-19917 and CVE-2019-19918
Summary: lout new security issues CVE-2019-19917 and CVE-2019-19918
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-10-30 19:28 CET by David Walser
Modified: 2021-01-17 12:54 CET (History)
7 users (show)

See Also:
Source RPM: lout-3.40-9.mga7.src.rpm
CVE: CVE-2019-19917, CVE-2019-19918
Status comment:


Attachments
txt file as copied from the tutorial (549 bytes, text/plain)
2020-11-09 11:59 CET, Herman Viaene
Details

Description David Walser 2020-10-30 19:28:56 CET
openSUSE has issued an advisory today (October 30):
https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00068.html

Mageia 7 is also affected.
David Walser 2020-10-30 19:34:13 CET

Whiteboard: (none) => MGA7TOO

Comment 1 David Walser 2020-10-31 14:16:18 CET
Fedora has issued an advisory for this today (October 31):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/QGZKTKGRJTQE43SFU77X5QJHKXTTOJYB/
Comment 2 Aurelien Oudelet 2020-10-31 17:49:41 CET
Hi, thanks for reporting this.
Assigned to recent commiter.

(Please set the status to 'assigned' if you are working on it)

Assignee: bugsquad => pkg-bugs
CC: (none) => olav, ouaurelien
Keywords: (none) => Triaged

Comment 3 Nicolas Salguero 2020-11-02 09:50:16 CET
Suggested advisory:
========================

The updated packages fix security vulnerabilities:

Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. (CVE-2019-19917)

Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c. (CVE-2019-19918)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19917
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19918
https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00068.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/QGZKTKGRJTQE43SFU77X5QJHKXTTOJYB/
========================

Updated packages in core/updates_testing:
========================
lout-3.40-9.1.mga7
lout-doc-3.40-9.1.mga7

from SRPM:
lout-3.40-9.1.mga7.src.rpm

Status: NEW => ASSIGNED
CVE: (none) => CVE-2019-19917, CVE-2019-19918
Version: Cauldron => 7
Whiteboard: MGA7TOO => (none)
Keywords: Triaged => (none)
CC: (none) => nicolas.salguero
Source RPM: lout-3.40-10.mga8.src.rpm => lout-3.40-9.mga7.src.rpm
Assignee: pkg-bugs => qa-bugs

Comment 4 Herman Viaene 2020-11-09 11:58:35 CET
MGA7_64 MATE on Peaq C1011
No installation issues.
No previous update, so Google brought me
http://www.adrianjwells.freeuk.com/lout.pdf
Took the first example (will upload this file) using pluma and run the command to create a pdf file.
$ lout louttest.txt > louttest.pdf
lout file "louttest.txt":
   4,149: character "\231" replaced by space (it has no glyph in font Times Base)
    6,39: character "\231" replaced by space (it has no glyph in font Times Base)
$ ls
lout.li  louttest.pdf  louttest.txt  louttest.txt.ld

The pdf file opens in Atril and looks OK. The .li file seems some kind of log, while the .ld file seems an exxpansion of the txt file with all the commands involved. I didn't read the tutorial further to check whether my interpretation is 100% correct
The command seems to do its job.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA7-64-OK

Comment 5 Herman Viaene 2020-11-09 11:59:34 CET
Created attachment 11983 [details]
txt file as copied from the tutorial
Comment 6 Thomas Andrews 2020-11-09 18:05:37 CET
Validated. Advisory in Comment 3.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Comment 7 Aurelien Oudelet 2020-11-10 09:29:13 CET
Advisory pushed to SVN.

Keywords: (none) => advisory

Comment 8 Mageia Robot 2020-11-10 16:21:26 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0411.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED

Comment 9 Zombie Ryushu 2021-01-17 12:35:44 CET
Xan anyone explain why this patch was not pushed to Cauldron as well?

CC: (none) => zombie_ryushu


Note You need to log in before you can comment on or make changes to this bug.