Bug 27561 - libexif new security issues CVE-2020-0181 and CVE-2020-0182
Summary: libexif new security issues CVE-2020-0181 and CVE-2020-0182
Status: RESOLVED DUPLICATE of bug 26814
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard: MGA7TOO
Keywords: Triaged
Depends on:
Blocks:
 
Reported: 2020-11-05 00:57 CET by David Walser
Modified: 2020-11-05 23:03 CET (History)
2 users (show)

See Also:
Source RPM: libexif-0.6.22-2.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-11-05 00:57:39 CET
RedHat has issued an advisory on November 3:
https://access.redhat.com/errata/RHSA-2020:4766

Mageia 7 is also affected.
David Walser 2020-11-05 00:57:46 CET

Whiteboard: (none) => MGA7TOO

Comment 1 Aurelien Oudelet 2020-11-05 09:31:49 CET
Hi, thanks for reporting this bug.
Assigned to all packagers, added recent commiters.

(Please set the status to 'assigned' if you are working on it)

Keywords: (none) => Triaged
CC: (none) => mageia, nicolas.salguero
Assignee: bugsquad => pkg-bugs

Comment 2 Nicolas Salguero 2020-11-05 10:58:18 CET
Hi,

According to RedHat and Debian the fix for CVE-2019-9278 and CVE-2020-0198 also fixed CVE-2020-0181.

Looking at the source code of version 0.6.22, I found that the fix for CVE-2020-0182 is already present in the code.

Best regards,

Nico.
Comment 3 David Walser 2020-11-05 23:03:29 CET
Agreed based on this:
https://git.centos.org/rpms/libexif/c/00b59c454861ef19aa3dfd26c6a7d0429fae37f9?branch=c8

*** This bug has been marked as a duplicate of bug 26814 ***

Resolution: (none) => DUPLICATE
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.