Bug 29821 - toxcore new security issue CVE-2021-44847
Summary: toxcore new security issue CVE-2021-44847
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-12-27 18:57 CET by David Walser
Modified: 2021-12-30 17:43 CET (History)
6 users (show)

See Also:
Source RPM: toxcore-0.2.12-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2021-12-27 18:57:04 CET
Fedora has issued an advisory today (December 27):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/S7EBS3NIRYJ7V3PTNINP3PJSVUHGZTGA/

The issue is fixed upstream in 0.2.13.

Mageia 8 is also affected.
David Walser 2021-12-27 18:57:18 CET

Status comment: (none) => Fixed upstream in 0.2.13
Whiteboard: (none) => MGA8TOO

Comment 1 Nicolas Lécureuil 2021-12-29 00:15:07 CET
new version pushed in mga9.


Fixed in mga8:

src:
    - toxcore-0.2.12-1.1.mga8

Whiteboard: MGA8TOO => (none)
Assignee: eatdirt => qa-bugs
CC: (none) => eatdirt, mageia
Status comment: Fixed upstream in 0.2.13 => (none)
Version: Cauldron => 8

Comment 2 David Walser 2021-12-29 00:18:02 CET
libtoxcore-devel-0.2.12-1.1.mga8
libtoxcore2-0.2.12-1.1.mga8

from toxcore-0.2.12-1.1.mga8.src.rpm
Comment 3 Herman Viaene 2021-12-29 16:20:14 CET
MGA8-64 Plasma on Lenovo B50 in Dutch
No installation issues.
Installed qtox to test
$ strace -o libtox.txt qtox
[15:13:53.012 UTC] persistence/db/rawdatabase.cpp:199 : Info: Opened database with SQLCipher "4.0 default" parameters
[ALSOFT] (WW) Querying error state on null context (implicitly 0xa004)
[15:13:53.815 UTC] net/updatecheck.cpp:139 : Info: Update available to version "v1.17.4"
[15:13:55.943 UTC] network.c:556 : Warning: unknown address type: 0

The qtoxwindow opened OK and I could add a new profile. Then rumaged around in the different tabs.
Checked the trace, found refs to libtoxcore.
OK for me.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 4 Thomas Andrews 2021-12-29 16:33:29 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2021-12-30 03:02:59 CET

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 5 Mageia Robot 2021-12-30 17:43:13 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0596.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.