Bug 30878 - python-mako new security issue CVE-2022-40023
Summary: python-mako new security issue CVE-2022-40023
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-09-21 18:05 CEST by David Walser
Modified: 2022-10-01 19:49 CEST (History)
7 users (show)

See Also:
Source RPM: python-mako-1.1.4-3.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-09-21 18:05:17 CEST
Ubuntu has issued an advisory today (September 21):
https://ubuntu.com/security/notices/USN-5625-1

The issue is fixed upstream in 1.2.2.

Mageia 8 is also affected.
David Walser 2022-09-21 18:05:35 CEST

Status comment: (none) => Fixed upstream in 1.2.2
Whiteboard: (none) => MGA8TOO

Comment 1 David Walser 2022-09-22 13:57:36 CEST
Debian-LTS has issued an advisory for this on September 21:
https://www.debian.org/lts/security/2022/dla-3116
Comment 2 Marja Van Waes 2022-09-22 15:42:50 CEST
Assigning to the python stack maintainers, CC'ing the registered maintainer.

Assignee: bugsquad => python
CC: (none) => makowski.mageia, marja11

Comment 3 papoteur 2022-09-22 16:39:32 CEST
Cauldron is updated
Update in Mageia 8 is coming.
python3-mako-1.2.2-1.mga8

Source: 
python-mako-1.2.2-1.mga8

Assignee: python => qa-bugs
Status comment: Fixed upstream in 1.2.2 => (none)
Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)
CC: (none) => yves.brungard_mageia

Comment 4 papoteur 2022-09-22 16:42:55 CEST
To know where it is used:
urpmq --whatrequires python3-mako
deluge
openlp
prewikka
pyff
python-gnuradio-runtime
python3-alembic
python3-catcher
python3-dogpile-cache
python3-mako
python3-opencl
python3-pecan
python3-pycuda
python3-zzzeeksphinx
wapiti
Extracts from description:
Mako is a template library written in Python. Mako's syntax and API borrows from the best ideas of many others, including Django templates, Cheetah, Myghty, and Genshi.
Comment 5 Herman Viaene 2022-09-26 11:16:51 CEST
MGA8-64 Plasma on Acer-Aspire 5253
No installation issues.
Tx papoteur for the pointers
$ strace -o mako.txt deluge
jumped a bit around in the menus, quit and checked output. Found a lot of references to /usr/lib/python3.8/site-packages/Mako-1.2.2-py3.8.egg-info/PKG-INFO
and similar ones.
Seems OK.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 6 Thomas Andrews 2022-09-26 14:14:42 CEST
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2022-10-01 16:32:04 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 7 Mageia Robot 2022-10-01 19:49:59 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0350.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.