Bug 29020 - slic3r new security issue CVE-2020-28591
Summary: slic3r new security issue CVE-2020-28591
Status: ASSIGNED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7TOO MGA7-64-OK
Keywords:
Depends on:
Blocks:
 
Reported: 2021-05-29 19:52 CEST by David Walser
Modified: 2021-06-16 15:31 CEST (History)
4 users (show)

See Also:
Source RPM: slic3r-1.3.0-7.mga9.src.rpm
CVE: CVE-2020-28591
Status comment:


Attachments

Description David Walser 2021-05-29 19:52:33 CEST
Fedora has issued an advisory on March 23:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TCSYYURJTUKJSEZIPDAXK4NHRXZMHIVA/

Mageia 7 and Mageia 8 are also affected.
David Walser 2021-05-29 19:52:47 CEST

Status comment: (none) => Patch available from Fedora
CC: (none) => geiger.david68210
Whiteboard: (none) => MGA8TOO, MGA7TOO

Comment 1 Lewis Smith 2021-05-29 22:00:47 CEST
No fixed maintainer; safest to assign this bug globally.

Assignee: bugsquad => pkg-bugs

Morgan Leijström 2021-05-30 01:35:29 CEST

CC: (none) => fri

Comment 2 Nicolas Salguero 2021-06-02 13:56:25 CEST
Suggested advisory:
========================

The updated package fixes a security vulnerability:

An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted AMF file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability. (CVE-2020-28591)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28591
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TCSYYURJTUKJSEZIPDAXK4NHRXZMHIVA/
========================

Updated package in 7/core/updates_testing:
========================
slic3r-1.3.0-1.1.mga7

from SRPM:
slic3r-1.3.0-1.1.mga7.src.rpm

Updated package in 8/core/updates_testing:
========================
slic3r-1.3.0-6.1.mga8

from SRPM:
slic3r-1.3.0-6.1.mga8.src.rpm

Version: Cauldron => 8
Assignee: pkg-bugs => qa-bugs
Whiteboard: MGA8TOO, MGA7TOO => MGA7TOO
CC: (none) => nicolas.salguero
CVE: (none) => CVE-2020-28591
Status comment: Patch available from Fedora => (none)
Status: NEW => ASSIGNED

Comment 3 Herman Viaene 2021-06-16 15:31:53 CEST
MGA7-64 Plasma on Lenovo B50
No installation issues.
As in bug 25473 Comment 6 I cannot really test this, because of lack of a 3D printer and knowlege on the subject.
But the command opens a proper GUI and goes thru a proper settings wizard, so OK for me.

CC: (none) => herman.viaene
Whiteboard: MGA7TOO => MGA7TOO MGA7-64-OK


Note You need to log in before you can comment on or make changes to this bug.