Fedora has issued an advisory on February 12: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/VACQYG356OHUTD5WQGAQ4L2TTFTAV3SJ/ The issue is fixed upstream in 1.4.19. Mageia 8 is also affected.
Whiteboard: (none) => MGA8TOOStatus comment: (none) => Fixed upstream in 1.4.19
Debian-LTS has issued an advisory for this on February 15: https://www.debian.org/lts/security/2022/dla-2924
openSUSE has issued an advisory for this on March 14: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BZZMZMEXJXNF2NQNIXETAFBVRAZVIVSO/
Upstream advisory for the original issue: https://github.com/x-stream/xstream/security/advisories/GHSA-rmr5-cpv2-vgjf Debian has issued an advisory on January 11: https://www.debian.org/security/2023/dsa-5315 The issue is fixed upstream in 1.4.20: https://github.com/x-stream/xstream/security/advisories/GHSA-j563-grx4-pjpv Mageia 8 is also affected.
Status comment: Fixed upstream in 1.4.19 => Fixed upstream in 1.4.20Summary: xstream new security issue CVE-2021-43859 => xstream new security issue CVE-2021-43859 and CVE-2022-41966
Summary: xstream new security issue CVE-2021-43859 and CVE-2022-41966 => xstream new security issues CVE-2021-43859 and CVE-2022-41966
Ubuntu has issued an advisory for CVE-2022-41966 today (March 13): https://ubuntu.com/security/notices/USN-5946-1
Done for Cauldron, freeze_move requested!
CC: (none) => geiger.david68210
xstream-1.4.20-1.mga9 moved.
Version: Cauldron => 8Whiteboard: MGA8TOO => (none)
Upstream advisory from December 24 for another issue fixed in 1.4.20: https://github.com/x-stream/xstream/security/advisories/GHSA-f8cc-g7j8-xxpm Alternate advisory links for the newer CVEs: https://x-stream.github.io/CVE-2022-40151.html https://x-stream.github.io/CVE-2022-41966.html SUSE has issued an advisory for this on March 29: https://lists.suse.com/pipermail/sle-security-updates/2023-March/014243.html
Summary: xstream new security issues CVE-2021-43859 and CVE-2022-41966 => xstream new security issues CVE-2021-43859, CVE-2022-40151, and CVE-2022-41966
Mageia 8 EOL
Resolution: (none) => OLDStatus: NEW => RESOLVEDCC: (none) => nicolas.salguero