Fedora has issued an advisory on September 24: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/7WQQBJ424DJMGRN6HI2OEMSSZ5XBG5ZH/ The issue is fixed upstream in 2.0.1. Mageia 8 is also affected.
Whiteboard: (none) => MGA8TOOStatus comment: (none) => Fixed upstream in 2.0.1
Assigning to all packagers collectively, since there is no registered maintainer for this package. CC'ing ovitters, because he's the only one, apart from umeabot, who touched this package in the last five years.
Assignee: bugsquad => pkg-bugsCC: (none) => marja11, olav
Suggested advisory: ======================== The updated packages fix a security vulnerability: Unsafe use of strncpy. (rhbz#1932066) References: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/7WQQBJ424DJMGRN6HI2OEMSSZ5XBG5ZH/ ======================== Updated packages in core/updates_testing: ======================== lib(64)ss7_2-2.0.1-1.mga8 lib(64)ss7-devel-2.0.1-1.mga8 from SRPM: libss7-2.0.1-1.mga8.src.rpm
Status: NEW => ASSIGNEDVersion: Cauldron => 8Whiteboard: MGA8TOO => (none)CC: (none) => nicolas.salgueroStatus comment: Fixed upstream in 2.0.1 => (none)Assignee: pkg-bugs => qa-bugs
MGA8-64 Plasma on Lenovo B50 No installation issues No previous updates, googling for an example draws a zero, and at CLI: ]# urpmq --whatrequires lib64ss7_2 lib64ss7-devel lib64ss7_2 # urpmq --whatrequires-recursive lib64ss7_2 lib64ss7-devel lib64ss7_2 OK'ing on clean install, unless someone's gor a better idea.
CC: (none) => herman.viaeneWhiteboard: (none) => MGA8-64-OK
I did the same yesterday. I did find a description of ss7 at https://en.wikipedia.org/wiki/Signalling_System_No._7 but have no idea if it is applicable. Too complicated to expect QA to master sufficiently to test, anyway. Clean install it is. Validating. Advisory in Comment 2.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
I should have known. As telephony is switching over to VOIP, I doubt there is still much use for ss7. In Belgium in analogue times (but computer controlled), ss7 was used to transfer info on call-setup and -duration from the switching exchange to a "Taxation Center" which calculated the cost of calls to be billed to the call-originator.
Keywords: (none) => advisoryCC: (none) => davidwhodgins
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0465.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED