Bug 27653 - pulseaudio new security issue CVE-2020-16123
Summary: pulseaudio new security issue CVE-2020-16123
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard: MGA7TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2020-11-23 20:01 CET by David Walser
Modified: 2020-11-23 21:16 CET (History)
3 users (show)

See Also:
Source RPM: pulseaudio-13.99.3-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-11-23 20:01:20 CET
Ubuntu has issued an advisory today (November 23):
https://ubuntu.com/security/notices/USN-4640-1

Mageia 7 is also affected.
David Walser 2020-11-23 20:01:26 CET

Whiteboard: (none) => MGA7TOO

Comment 1 Aurelien Oudelet 2020-11-23 20:12:06 CET
An Ubuntu-specific patch caused PulseAudio to incorrectly handle snap client connections.
Do we provide this?
http://svnweb.mageia.org/packages/cauldron/pulseaudio/current/SPECS/pulseaudio.spec?revision=1641577&view=markup

I am not an expert but I don't see this in SPEC file.

CC: (none) => ouaurelien

Comment 2 Aurelien Oudelet 2020-11-23 20:15:43 CET
Meanwhile, assigning to all packagers.
Cc'd recent commiter.

Assignee: bugsquad => pkg-bugs
CC: (none) => geiger.david68210, jani.valimaa

Comment 3 David Walser 2020-11-23 21:05:34 CET
Thanks, sorry for the noise.

Resolution: (none) => INVALID
Status: NEW => RESOLVED

Comment 4 Aurelien Oudelet 2020-11-23 21:16:21 CET
Meanwhile (again) PulseAudio 14.0 is released.
https://www.freedesktop.org/wiki/Software/PulseAudio/Notes/14.0/

Note You need to log in before you can comment on or make changes to this bug.