Bug 30204 - zlib new security issue CVE-2018-25032
Summary: zlib new security issue CVE-2018-25032
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-03-24 14:30 CET by David Walser
Modified: 2022-03-31 21:56 CEST (History)
4 users (show)

See Also:
Source RPM: zlib-1.2.11-11.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-03-24 14:30:58 CET
A commit in zlib's upstream git from four years ago, which has not yet made it into a release, has been identified as fixing a security issue:
https://www.openwall.com/lists/oss-security/2022/03/24/1

I suspect we'll see a CVE for it shortly.

Mageia 8 is also affected.
Comment 1 Thomas Backlund 2022-03-24 17:03:59 CET
SRPM:
zlib-1.2.11-9.1.mga8.src.rpm


i586:
libminizip1-1.2.11-9.1.mga8.i586.rpm
libminizip-devel-1.2.11-9.1.mga8.i586.rpm
libzlib1-1.2.11-9.1.mga8.i586.rpm
libzlib-devel-1.2.11-9.1.mga8.i586.rpm
libzlib-static-devel-1.2.11-9.1.mga8.i586.rpm


x86_64:
lib64minizip1-1.2.11-9.1.mga8.x86_64.rpm
lib64minizip-devel-1.2.11-9.1.mga8.x86_64.rpm
lib64zlib1-1.2.11-9.1.mga8.x86_64.rpm
lib64zlib-devel-1.2.11-9.1.mga8.x86_64.rpm
lib64zlib-static-devel-1.2.11-9.1.mga8.x86_64.rpm

Version: Cauldron => 8
Assignee: bugsquad => qa-bugs

Comment 2 Thomas Backlund 2022-03-25 19:01:39 CET
It now have a CVE
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25032
David Walser 2022-03-25 20:51:46 CET

Summary: zlib new security issue fixed upstream => zlib new security issue CVE-2018-25032

Comment 3 Herman Viaene 2022-03-26 15:05:26 CET
MGA8-64 Plasma on Lenovo B50 in Dutch
No installattion issues.
Ref bug 19529 for tests, but I run into problems with qt-fsarchiver (it wants a qt-fsarchiver-terminal which I do nt find), and with nmapfe that does not exists (anymore?) at all.

CC: (none) => herman.viaene

Comment 4 David Walser 2022-03-26 17:07:53 CET
(In reply to Thomas Backlund from comment #2)
> It now have a CVE
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25032

Reference:
https://www.openwall.com/lists/oss-security/2022/03/25/2
Comment 5 Thomas Backlund 2022-03-30 13:02:53 CEST
I think I'll rebase to recently released 1.2.12 to pick up the other bugfixes at the same time...

Keywords: (none) => feedback

Comment 6 Thomas Backlund 2022-03-30 14:13:00 CEST
Changelog for 1.2.12:
https://www.zlib.net/ChangeLog.txt

new rpms:

SRPM:
zlib-1.2.12-1.mga8.src.rpm


i586:
libminizip1-1.2.12-1.mga8.i586.rpm
libminizip-devel-1.2.12-1.mga8.i586.rpm
libzlib1-1.2.12-1.mga8.i586.rpm
libzlib-devel-1.2.12-1.mga8.i586.rpm
libzlib-static-devel-1.2.12-1.mga8.i586.rpm


x86_64:
lib64minizip1-1.2.12-1.mga8.x86_64.rpm
lib64minizip-devel-1.2.12-1.mga8.x86_64.rpm
lib64zlib1-1.2.12-1.mga8.x86_64.rpm
lib64zlib-devel-1.2.12-1.mga8.x86_64.rpm
lib64zlib-static-devel-1.2.12-1.mga8.x86_64.rpm

Keywords: feedback => (none)

Comment 7 Thomas Andrews 2022-03-30 18:21:25 CEST
(In reply to Herman Viaene from comment #3)
> MGA8-64 Plasma on Lenovo B50 in Dutch
> No installattion issues.
> Ref bug 19529 for tests, but I run into problems with qt-fsarchiver (it
> wants a qt-fsarchiver-terminal which I do nt find), and with nmapfe that
> does not exists (anymore?) at all.

The following 3 packages are going to be installed:

- lib64minizip1-1.2.12-1.mga8.x86_64
- lib64zlib-devel-1.2.12-1.mga8.x86_64
- lib64zlib1-1.2.12-1.mga8.x86_64

MGA8-64 Plasma in English. No installation issues here, either.

Looked over Bug 19529. Since fsarchiver is having issues, I decided to try something else: Handbrake.

$ strace -o zlib.txt ghb

Converted three videos from various container types to .mp4. Examined the resulting strace file, and found one reference to /lib64/libz.so.1.

Did another strace with Ark, where I extracted some screenshots from a tar.gz file, and there I again found a single reference to libz.so.1.

Looks OK to me. Validating.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2022-03-31 20:47:47 CEST

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 8 David Walser 2022-03-31 21:11:59 CEST
Ubuntu has issued an advisory for this on March 30:
https://ubuntu.com/security/notices/USN-5355-1
Comment 9 Mageia Robot 2022-03-31 21:56:39 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0124.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.