Bug 27735 - checkstyle new security issue CVE-2019-10782
Summary: checkstyle new security issue CVE-2019-10782
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Nicolas Lécureuil
QA Contact: Sec team
URL: https://nvd.nist.gov/vuln/detail/CVE-...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-12-04 10:37 CET by Zombie Ryushu
Modified: 2021-07-01 18:25 CEST (History)
1 user (show)

See Also:
Source RPM: checkstyle-8.0-3.mga7.src.rpm
CVE: CVE-2019-10782
Status comment: Patch checked into SVN


Attachments

Description Zombie Ryushu 2020-12-04 10:37:38 CET
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
Zombie Ryushu 2020-12-04 10:38:26 CET

CVE: (none) => CVE-2019-10782

Comment 1 David Walser 2020-12-04 13:34:29 CET
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10782

Package dropped in Cauldron.

Source RPM: checkstyle => checkstyle-8.0-3.mga7.src.rpm
Summary: checkstyle security vulnerability CVE-2019-10782 => checkstyle new security issue CVE-2019-10782

Comment 2 Aurelien Oudelet 2020-12-07 10:39:12 CET
Hi, thanks for reporting this.
Assigned to the package maintainer.

(Please set the status to 'assigned' if you are working on it)

CC: (none) => ouaurelien
Assignee: bugsquad => mageia

Comment 3 David Walser 2020-12-28 19:10:39 CET
Debian-LTS has issued an advisory for this on February 10:
https://www.debian.org/lts/security/2020/dla-2099

This was actually filed as Bug 26219 before, but wrongly closed.
David Walser 2020-12-28 19:10:58 CET

Status comment: (none) => Patch available from Debian

Comment 4 David Walser 2021-06-28 22:31:50 CEST
Patched checked into Mageia 7.  This is Java stuff that isn't really used by anything, so I don't think it's worth pushing an update, but feel free to push to the build system if you disagree.

Status comment: Patch available from Debian => Patch checked into SVN

Comment 5 David Walser 2021-07-01 18:25:18 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.