Bug 28926 - rpm new security issues (including CVE-2021-3421, CVE-2021-20266, and CVE-2021-20271)
Summary: rpm new security issues (including CVE-2021-3421, CVE-2021-20266, and CVE-202...
Status: RESOLVED DUPLICATE of bug 28674
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Thierry Vignaud
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-05-15 00:21 CEST by David Walser
Modified: 2021-07-02 09:09 CEST (History)
0 users

See Also:
Source RPM: rpm-4.16.1.2-1.mga8.src.rpm
CVE:
Status comment: Fixed upstream in 4.16.1.3


Attachments

Description David Walser 2021-05-15 00:21:55 CEST
Security issues found in RPM have been announced on May 4:
https://www.openwall.com/lists/oss-security/2021/05/04/2

One of these is CVE-2021-20271:
https://bugzilla.redhat.com/show_bug.cgi?id=1934125

I'm not sure about the other one.

Mageia 7 and Mageia 8 are also affected.
David Walser 2021-05-15 00:22:02 CEST

Whiteboard: (none) => MGA8TOO, MGA7TOO

Comment 1 David Walser 2021-05-29 20:42:36 CEST
Fedora has issued an advisory for this on March 30:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/

I believe these are fixed in 4.16.1.3.

Whiteboard: MGA8TOO, MGA7TOO => MGA7TOO
Summary: rpm new security issues (include CVE-2021-20271) => rpm new security issues (including CVE-2021-3421, CVE-2021-20266, and CVE-2021-20271)
Status comment: (none) => Fixed upstream in 4.16.1.3
Source RPM: rpm-4.16.1.3-3.mga9.src.rpm => rpm-4.16.1.2-1.mga8.src.rpm
Version: Cauldron => 8

Comment 2 David Walser 2021-07-01 18:50:56 CEST
Removing Mageia 7 from whiteboard due to EOL:
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Whiteboard: MGA7TOO => (none)

Comment 3 Thierry Vignaud 2021-07-02 09:08:30 CEST
We're covered by https://advisories.mageia.org/MGASA-2021-0167.html then

*** This bug has been marked as a duplicate of bug 28674 ***

Status: NEW => RESOLVED
Resolution: (none) => DUPLICATE

Comment 4 Thierry Vignaud 2021-07-02 09:09:50 CEST
(unless you want to push an empty advisory?)
(the details are in https://rpm.org/wiki/Releases/4.16.1.3)

Note You need to log in before you can comment on or make changes to this bug.