Bug 29307 - freeciv new security issue fixed upstream in 2.6.7 (CVE-2022-39047)
Summary: freeciv new security issue fixed upstream in 2.6.7 (CVE-2022-39047)
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: https://freeciv.fandom.com/wiki/NEWS-...
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-07-31 13:59 CEST by Zombie Ryushu
Modified: 2022-08-31 22:56 CEST (History)
6 users (show)

See Also:
Source RPM: freeciv-2.6.3-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description Zombie Ryushu 2021-07-31 13:59:41 CEST
2.6.5 is a bugfix release. Notably it fixes regression in 2.6.4 gtk3-client that present units in city dialog had no overlays drawn at all.
Server / General
Changes affecting players (supplied rulesets)

    Allow goto to a moving transport (but not through one) HRM#647612
    Less predictable random seed supported on more platforms
        On experimental msys2 based builds on Windows. Msys1 environment used for the official Windows builds does not provide interfaces required for this support osdn#41842 osdn#41995 osdn#42000
        Older Linux osdn#41918 osdn#42024
    Air unit goto avoids wait for refuel when it's not necessary HRM#923677 osdn#42029
    Server does not send city info to clients in the middle of calculations where the info might be inconsistent osdn#41851 osdn#41975
    Already built buildings are purged from the worklist. They used to be just postponed osdn#41925
    Terrain changing unit activities are cancelled when climate change changes tile terrain. With the new terrain the target of those actions is not what was started HRM#899919
    Avoid endless loop with scenarios having bad starting positions HRM#767127
    Server correctly informs client when loading a savegame fails. It used to always claim that load was succesfull to the client osdn#42189
    Game refuses paradropping to a tile with known enemy unit as that would only be certain death for the paradropping unit HRM#869995
    Fixed a bug that when player providing shared vision was removed, the vision would remain for the other players HRM#883225
    Corrected bribe cost of units with build cost not multiple of ten. Especially this makes bribe cost of units with build cost less than ten not to be zero. HRM#929034
    Avoid server getting stuck when loading ruleset that has unit obsoletion loop osdn#42301

    civ1
        Made traderoute one-time-bonus gold only osdn#42317

Changes affecting other rulesets / modders

    When calculating action success chance, surviving tech requirements on World range are known to be known by everyone HRM#922369
    Fixed scorelog start check to work correctly with ruleset set start year other than default HRM#820731
    Fixed server crash when illness destroys a city. That can happen only with rulesets that enable illness for size 1 cities osdn#41959
    Server now checks that unit's transport can hold the target unit before converting unit HRM#921940
    Terrain transform time of zero now really disables transforming, as documented osdn#42120

General

    Minor optimizations HRM#921195 osdn#42331
    Various internal changes which should only affect developers osdn#41764 osdn#41852 HRM#923660 osdn#41772 osdn#41873 osdn#41847 osdn#41953 osdn#42006 osdn#41937 osdn#42098 osdn#42045 osdn#42053 osdn#42101 osdn#42117 osdn#42142 osdn#42192 osdn#42346 osdn#42325 osdn#42043 osdn#41947 osdn#42340 HRM#909607 osdn#42421 osdn#42461 osdn#42456

AI

    Better air unit handling HRM#924327
    Better evaluate value of transports filled with cargo for the invasion attempt HRM#872215
    AI puts more weight on potential improvement's gold effect (including upkeep) when it's short of gold osdn#42195
    Corrected actual AI's use of advisor when it's evaluating governments osdn#42231
    Stopped fueled units from unnecessary hopping between bases when they should regenerate HRM#924328
    Fixed rare AI crash when tech upkeep was enabled and a player had researched zero techs osdn#42409
Comment 1 Lewis Smith 2021-08-01 20:27:38 CEST
Thanks for the information.
This SRPM is committed by various people, so assigning this request globally.

Assignee: bugsquad => pkg-bugs

Comment 2 David Walser 2022-08-05 18:22:37 CEST
A security issue fixed upstream in 2.6.7 has been announced today (August 5):
https://www.openwall.com/lists/oss-security/2022/08/05/1

This package probably should be dropped in Cauldron, as the maintainer left Mageia (unless someone else wants to maintain it going forward).

QA Contact: (none) => security
URL: https://freeciv.fandom.com/wiki/NEWS-2.6.5 => https://freeciv.fandom.com/wiki/NEWS-2.6.7
Summary: [Update Request] freeciv 2.6.5 => freeciv new security issue fixed upstream in 2.6.7
Whiteboard: (none) => MGA8TOO
Version: 8 => Cauldron
Component: RPM Packages => Security

Comment 3 David Walser 2022-08-15 02:35:37 CEST
Fedora has issued an advisory for this today (August 14):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/HLT5I3HABQCHJQXRBN4ABVGHCP3LW5QT/
Comment 4 Nicolas Salguero 2022-08-23 12:12:35 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Modpack Installer buffer overflow.

References:
https://www.openwall.com/lists/oss-security/2022/08/05/1
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/HLT5I3HABQCHJQXRBN4ABVGHCP3LW5QT/
========================

Updated packages in core/updates_testing:
========================
freeciv-client-2.6.7-1.mga8
freeciv-data-2.6.7-1.mga8
freeciv-server-2.6.7-1.mga8

from SRPM:
freeciv-2.6.7-1.mga8.src.rpm

Status: NEW => ASSIGNED
Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8
Source RPM: freeciv-2.6.3-1.src.rpm => freeciv-2.6.3-1.mga8.src.rpm
CC: (none) => nicolas.salguero
Assignee: pkg-bugs => qa-bugs

Comment 5 Herman Viaene 2022-08-24 09:41:36 CEST
MGA8-64 Plasma on Aceer Aspire 5253
No installation issues.
I could move a little around in a local play (freeciv-qt), and run the server and connect from the client and start a game.
Not really knowing what to do inside the game, but I can move and get a soundtrack playing.
OK for me.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA8-64-OK

Comment 6 Thomas Andrews 2022-08-24 13:29:04 CEST
Validating. Advisory in Comment 4.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 7 David Walser 2022-08-24 21:39:48 CEST
openSUSE has issued an advisory for this today (August 24):
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FGIIGXHCBJ6BXOPVIKR6NCU4TUBJIYLP/

It now has a CVE (CVE-2022-6083).

Summary: freeciv new security issue fixed upstream in 2.6.7 => freeciv new security issue fixed upstream in 2.6.7 (CVE-2022-6083)

Dave Hodgins 2022-08-24 23:07:10 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 8 Mageia Robot 2022-08-25 23:22:39 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0293.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED

Comment 9 David Walser 2022-08-31 22:35:54 CEST
(In reply to David Walser from comment #7)
> openSUSE has issued an advisory for this today (August 24):
> https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.
> org/thread/FGIIGXHCBJ6BXOPVIKR6NCU4TUBJIYLP/
> 
> It now has a CVE (CVE-2022-6083).

possibly also CVE-2022-39047:
https://www.openwall.com/lists/oss-security/2022/08/31/1

I e-mailed Salvatore and let him know about the other CVE.

CC: (none) => luigiwalser

Comment 10 David Walser 2022-08-31 22:56:37 CEST
Salvatore's response:
"CVE-2022-6083 is not the correct CVE. Apparently Red Hat and SuSE have
picked them up due to a mentioning in the Debian bug #1017579.

This mentioning was initially caused by our triage in Debian as

https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/398004c7ad5fc8f0fad60ac7b3e52d8ebd1c018c

but this was just a typo and got corrected in

https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2b912d134208da4659d9ba2537fb8a31548c8030

later then the CVE-2022-39047 got assigned by MITRE."

I changed the CVE in our SVN advisory.

Summary: freeciv new security issue fixed upstream in 2.6.7 (CVE-2022-6083) => freeciv new security issue fixed upstream in 2.6.7 (CVE-2022-39047)


Note You need to log in before you can comment on or make changes to this bug.