Bug 29092 - libgrss new security issue CVE-2016-20011
Summary: libgrss new security issue CVE-2016-20011
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7TOO MGA7-64-OK MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-06-08 03:09 CEST by David Walser
Modified: 2021-07-12 22:27 CEST (History)
4 users (show)

See Also:
Source RPM: libgrss-0.7.0-4.mga8.src.rpm
CVE: CVE-2016-20011
Status comment:


Attachments

Description David Walser 2021-06-08 03:09:00 CEST
A security issue in libgrss has been reported:
https://bugzilla.gnome.org/show_bug.cgi?id=772647
https://gitlab.gnome.org/GNOME/libgrss/-/issues/4

A patch to mitigate the issue is available at:
https://gitlab.gnome.org/GNOME/libgrss/-/merge_requests/7.patch

Mageia 7 and Mageia 8 are also affected.
David Walser 2021-06-08 03:09:07 CEST

Whiteboard: (none) => MGA8TOO, MGA7TOO

Comment 1 Lewis Smith 2021-06-08 21:43:39 CEST
Olav is both registered & active maintainer of this, so assigning the bug accordingly.

Assignee: bugsquad => olav

Comment 2 David Walser 2021-06-28 20:02:28 CEST
Advisory:
========================

Updated libgrss packages fix security vulnerability:

libgrss does not perform any TLS certificate verification because it uses the
deprecated SoupSessionAsync, which requires manually enabling certificate
verification, rather than a modern SoupSession that has good defaults
(CVE-2016-20011).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-20011
https://gitlab.gnome.org/GNOME/libgrss/-/issues/4
========================

Updated packages in core/updates_testing:
========================
libgrss0-0.7.0-2.1.mga7
libgrss-devel-0.7.0-2.1.mga7
libgrss0-0.7.0-4.1.mga8
libgrss-devel-0.7.0-4.1.mga8

from SRPMS:
libgrss-0.7.0-2.1.mga7.src.rpm
libgrss-0.7.0-4.1.mga8.src.rpm

Version: Cauldron => 8
Assignee: olav => qa-bugs
Whiteboard: MGA8TOO, MGA7TOO => MGA7TOO

Comment 3 Herman Viaene 2021-07-09 10:52:42 CEST
MGA7-64 Plasma on Lenovo B50
No installation issues, no previous updates on this.
# urpmq --whatrequires lib64grss0
lib64grss0
tracker-miners
That's the same league as the update on libosinfo in bug 25112, so again OK on clean install.

CC: (none) => herman.viaene
Whiteboard: MGA7TOO => MGA7TOO MGA7-64-OK

Comment 4 Herman Viaene 2021-07-12 13:38:06 CEST
MGA8-64 Plasma on Lenovo B50
No installation issues.
Clean install. OK.

Whiteboard: MGA7TOO MGA7-64-OK => MGA7TOO MGA7-64-OK MGA8-64-OK

Comment 5 Thomas Andrews 2021-07-12 14:59:14 CEST
Validating. Advisory in Comment 2.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Aurelien Oudelet 2021-07-12 20:53:36 CEST

Keywords: (none) => advisory
CC: (none) => ouaurelien
CVE: (none) => CVE-2016-20011

Comment 6 Mageia Robot 2021-07-12 22:27:50 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0343.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.