Bug 30058 - kcron new security issue CVE-2022-24986
Summary: kcron new security issue CVE-2022-24986
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: KDE maintainers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-02-16 23:50 CET by David Walser
Modified: 2024-01-12 09:41 CET (History)
2 users (show)

See Also:
Source RPM: kcron-21.12.0-1.mga9.src.rpm
CVE:
Status comment: Fixed upstream in 21.12.3


Attachments

Description David Walser 2022-02-16 23:50:27 CET
KDE has issued an advisory today (February 16):
https://kde.org/info/security/advisory-20220216-1.txt

The issue is fixed upstream in 21.12.3.

Mageia 8 is also affected.
David Walser 2022-02-16 23:50:57 CET

Status comment: (none) => Fixed upstream in 21.12.3
Whiteboard: (none) => MGA8TOO

Nicolas Lécureuil 2022-02-17 00:52:18 CET

Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8
CC: (none) => mageia

Comment 1 David Walser 2022-02-17 00:54:47 CET
Fixed in kcron-21.12.0-2.mga9.
Comment 2 David Walser 2022-02-25 16:16:50 CET
Detailed analysis:
https://www.openwall.com/lists/oss-security/2022/02/25/3
Comment 3 Nicolas Salguero 2024-01-12 09:41:00 CET
Mageia 8 EOL

Resolution: (none) => OLD
CC: (none) => nicolas.salguero
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.