Bug 30450 - yajl, mongo-c-driver new security issue CVE-2022-24795
Summary: yajl, mongo-c-driver new security issue CVE-2022-24795
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: papoteur
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on: 32072
Blocks:
  Show dependency treegraph
 
Reported: 2022-05-19 18:52 CEST by David Walser
Modified: 2024-01-12 09:53 CET (History)
3 users (show)

See Also:
Source RPM: yajl-2.1.0-3.mga8.src.rpm, mongo-c-driver-1.17.3-1.mga8.src.rpm
CVE:
Status comment: yajl patched, mongo-c-driver still needs to be patched


Attachments

Description David Walser 2022-05-19 18:52:21 CEST
SUSE has issued an advisory today (May 19):
https://lists.suse.com/pipermail/sle-security-updates/2022-May/011095.html

libbson (part of the mongo-c-driver SRPM) is also affected.

Mageia 8 is also affected.
David Walser 2022-05-19 18:52:55 CEST

Whiteboard: (none) => MGA8TOO

Comment 1 Lewis Smith 2022-05-19 21:58:10 CEST
yajl is a homeless package, so assigning this update globally for that.

mongo-c-driver is done by Guillaume, so CC'ing you for that. But you might perhaps also do the yajl part?.

CC: (none) => guillomovitch
Assignee: bugsquad => pkg-bugs

Comment 2 papoteur 2022-07-06 09:38:59 CEST
For yajl, cauldron is updated.
In mageia 8, there is now:

lib64yajl2-2.1.0-4.mga8
yajl-2.1.0-4.mga8
lib64yajl-devel-2.1.0-4.mga8

From the source:
yajl-2.1.0-4.mga8.src.rpm

Assignee: pkg-bugs => qa-bugs
Version: Cauldron => 8
CC: (none) => yves.brungard_mageia
Whiteboard: MGA8TOO => (none)

Comment 3 papoteur 2022-07-06 09:41:37 CEST
I see that mongo-c-driver is updated to 1.21.2 in cauldron but has not been touched in Mageia 8
Comment 4 David Walser 2022-07-06 16:44:18 CEST
Assigning back to papoteur, as mongo-c-driver has not been fixed yet.

Status comment: (none) => yajl patched, mongo-c-driver still needs to be patched
Assignee: qa-bugs => yves.brungard_mageia

Comment 5 David Walser 2022-11-08 13:38:17 CET
RedHat has issued an advisory for this today (November 8):
https://access.redhat.com/errata/RHSA-2022:7524
David Walser 2023-07-05 22:52:01 CEST

Depends on: (none) => 32072

Comment 6 Nicolas Salguero 2024-01-12 09:53:20 CET
Mageia 8 EOL

Resolution: (none) => OLD
CC: (none) => nicolas.salguero
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.