Bug 29250 - openscad new security issue CVE-2020-28600
Summary: openscad new security issue CVE-2020-28600
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Rémi Verschelde
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-07-12 17:32 CEST by David Walser
Modified: 2021-12-14 19:07 CET (History)
1 user (show)

See Also:
Source RPM: openscad-2021.01-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2021-07-12 17:32:01 CEST
openSUSE has issued an advisory on July 11:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TD6AL34245BXDPEWDDFP4UJMOIXTZWMV/

Mageia 8 is also affected.
David Walser 2021-07-12 17:32:31 CEST

CC: (none) => mageia
Whiteboard: (none) => MGA8TOO
Status comment: (none) => Patch available from openSUSE

Comment 1 Lewis Smith 2021-07-13 10:15:03 CEST
akien is registered & an active maintainer of this pkg, so assigning to you.

Assignee: bugsquad => rverschelde

Comment 2 Nicolas Lécureuil 2021-12-14 19:01:05 CET
already fixed in the version openscad-2021.01 we have in mga 8/9.

This is fixed by the commit:  https://github.com/openscad/openscad/commit/07ea60f82e94a155f4926f17fad8e8366bc74874

Status comment: Patch available from openSUSE => (none)
Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 3 David Walser 2021-12-14 19:07:02 CET
Indeed, SUSE bug says as much now too.  That makes this INVALID.

Resolution: FIXED => INVALID
Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8


Note You need to log in before you can comment on or make changes to this bug.