Bug 30216 - perl-DBD-SQLite possible unfixed security issues due to bundled sqlite3
Summary: perl-DBD-SQLite possible unfixed security issues due to bundled sqlite3
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-03-29 00:56 CEST by David Walser
Modified: 2023-07-07 07:56 CEST (History)
6 users (show)

See Also:
Source RPM: perl-DBD-SQLite-1.700.0-2.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-03-29 00:56:21 CEST
openSUSE has issued an advisory today (March 28):
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VRQ7IRKZITJLT44RH5PJICZIIRQJLXEE/

While our package does BR pkgconfig(sqlite3), the built package isn't linked against the library, so more needs to be done (whatever SUSE did).

Mageia 8 is also affected.
Comment 1 David Walser 2022-03-29 00:57:03 CEST
I don't know what the deal is with the similarly named perl-DBD-SQLite2 package.

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Needs to be linked against system sqlite3 library

Comment 2 Lewis Smith 2022-03-29 21:29:43 CEST
No obvious packager for this, so assigning it 'perl'; CC'ing tv who updated perl-DBD-SQLite most recently.

Assignee: bugsquad => perl
CC: (none) => thierry.vignaud

Comment 3 David GEIGER 2023-06-29 20:47:24 CEST
Assigning to QA,

Packages in 9/Core/Updates_testing:
======================
perl-DBD-SQLite-1.720.0-2.mga9

Packages in 8/Core/Updates_testing:
======================
perl-DBD-SQLite-1.660.0-1.1.mga8


From SRPMS:
perl-DBD-SQLite-1.720.0-2.mga9.src.rpm
perl-DBD-SQLite-1.660.0-1.1.mga8.src.rpm

Assignee: perl => qa-bugs
CC: (none) => geiger.david68210

David Walser 2023-06-29 23:02:06 CEST

Status comment: Needs to be linked against system sqlite3 library => (none)

Comment 4 David GEIGER 2023-06-30 16:50:38 CEST
Packages moved to Core/Release for cauldron!

Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)

Comment 5 Herman Viaene 2023-07-03 15:33:27 CEST
MGA8-64 MATE on Acer Aspire 5253
No istallation issues.
Ref bug 17218 shows auto-multiple-choice as dependent on it.
Run auto-multiple-choice, seems to be OK.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 6 Thomas Andrews 2023-07-06 02:02:20 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2023-07-06 22:48:48 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 7 Mageia Robot 2023-07-07 07:56:15 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0214.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.