Fedora has issued an advisory on March 23: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TCSYYURJTUKJSEZIPDAXK4NHRXZMHIVA/ Mageia 7 and Mageia 8 are also affected.
CC: (none) => geiger.david68210Status comment: (none) => Patch available from FedoraWhiteboard: (none) => MGA8TOO, MGA7TOO
No fixed maintainer; safest to assign this bug globally.
Assignee: bugsquad => pkg-bugs
CC: (none) => fri
Suggested advisory: ======================== The updated package fixes a security vulnerability: An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted AMF file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability. (CVE-2020-28591) References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28591 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TCSYYURJTUKJSEZIPDAXK4NHRXZMHIVA/ ======================== Updated package in 7/core/updates_testing: ======================== slic3r-1.3.0-1.1.mga7 from SRPM: slic3r-1.3.0-1.1.mga7.src.rpm Updated package in 8/core/updates_testing: ======================== slic3r-1.3.0-6.1.mga8 from SRPM: slic3r-1.3.0-6.1.mga8.src.rpm
CVE: (none) => CVE-2020-28591CC: (none) => nicolas.salgueroStatus comment: Patch available from Fedora => (none)Status: NEW => ASSIGNEDVersion: Cauldron => 8Whiteboard: MGA8TOO, MGA7TOO => MGA7TOOAssignee: pkg-bugs => qa-bugs
MGA7-64 Plasma on Lenovo B50 No installation issues. As in bug 25473 Comment 6 I cannot really test this, because of lack of a 3D printer and knowlege on the subject. But the command opens a proper GUI and goes thru a proper settings wizard, so OK for me.
Whiteboard: MGA7TOO => MGA7TOO MGA7-64-OKCC: (none) => herman.viaene
MGA8-64 Plasma on Lenovo B50 No installation issues. Same test and result as Comment 3, OK for me.
Whiteboard: MGA7TOO MGA7-64-OK => MGA7TOO MGA7-64-OK MGA8-64-OK
I'm unaware of anyone in QA with a 3D printer, So it looks as if you've done as well with tis one as any of us, Herman. Validating. Advisory in Comment 2.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
Keywords: (none) => advisorySource RPM: slic3r-1.3.0-7.mga9.src.rpm => slic3r-1.3.0-6.mga8.src.rpmCC: (none) => ouaurelien
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0276.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED