Apache has issued advisories on June 12: https://www.openwall.com/lists/oss-security/2021/06/12/2 https://www.openwall.com/lists/oss-security/2021/06/12/1 The issues are fixed upstream in 2.0.24. Mageia 7 and Mageia 8 are also affected.
Whiteboard: (none) => MGA8TOO, MGA7TOOBlocks: (none) => 28708Status comment: (none) => Fixed upstream in 2.0.24
Fedora has issued an advisory for this today (June 24): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MDJKJQOMVFDFIDS27OQJXNOYHV2O273D/
Removing Mageia 7 from whiteboard due to EOL: https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/
Whiteboard: MGA8TOO, MGA7TOO => MGA8TOO
new version pushed in mga8/9 src: - pdfbox-2.0.24-1.mga8
Assignee: java => qa-bugsCC: (none) => mageiaStatus comment: Fixed upstream in 2.0.24 => (none)
pdfbox-2.0.24-1.mga8 pdfbox-debugger-2.0.24-1.mga8 fontbox-2.0.24-1.mga8 preflight-2.0.24-1.mga8 xmpbox-2.0.24-1.mga8 pdfbox-tools-2.0.24-1.mga8 pdfbox-parent-2.0.24-1.mga8 pdfbox-reactor-2.0.24-1.mga8 pdfbox-javadoc-2.0.24-1.mga8 from pdfbox-2.0.24-1.mga8.src.rpm
Version: Cauldron => 8Whiteboard: MGA8TOO => (none)
Advisory: ======================== In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions (CVE-2021-31811). In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions (CVE-2021-31812). References: - https://bugs.mageia.org/show_bug.cgi?id=29125 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31811 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31812 - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MDJKJQOMVFDFIDS27OQJXNOYHV2O273D/ ======================== Updated packages in core/updates_testing: ======================== pdfbox-2.0.24-1.mga8 pdfbox-debugger-2.0.24-1.mga8 fontbox-2.0.24-1.mga8 preflight-2.0.24-1.mga8 xmpbox-2.0.24-1.mga8 pdfbox-tools-2.0.24-1.mga8 pdfbox-parent-2.0.24-1.mga8 pdfbox-reactor-2.0.24-1.mga8 pdfbox-javadoc-2.0.24-1.mga8 from pdfbox-2.0.24-1.mga8.src.rpm
CC: (none) => ouaurelien
MGA8-64 Plasma on Lenovo B50 No installation issues. Ref bug 28682 where our boss recommends OK on clean install. I won't contradict him.
Whiteboard: (none) => MGA8-64-OKCC: (none) => herman.viaene
Good to know there's no dissension in the ranks. Validating. Advisory in Comment 5.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => advisoryCVE: (none) => CVE-2021-3181[12]
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0378.html
Status: NEW => RESOLVEDResolution: (none) => FIXED