Bug 30900 - libofx new security issue rhbz#2127755
Summary: libofx new security issue rhbz#2127755
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-09-27 00:23 CEST by David Walser
Modified: 2022-10-13 22:06 CEST (History)
4 users (show)

See Also:
Source RPM: libofx-0.9.15-2.mga8.src.rpm
CVE:
Status comment:


Attachments
sample ofx file (590 bytes, text/plain)
2022-10-12 03:52 CEST, Thomas Andrews
Details

Description David Walser 2022-09-27 00:23:41 CEST
Fedora has issued an advisory on September 24:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/YP7TQYRM2UPP5R5NKSEGDFKJARD7VN4A/

Mageia 8 may also be affected.
David Walser 2022-09-27 00:24:03 CEST

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Patches available from Fedora

Comment 1 Lewis Smith 2022-09-28 19:48:26 CEST
No one packager evident, so assigning this globally.

Assignee: bugsquad => pkg-bugs
Source RPM: (none) => libofx-0.10.7.mga8.src.rpm

Comment 3 David Walser 2022-09-28 20:00:21 CEST
More info:
https://bugzilla.redhat.com/show_bug.cgi?id=2130201
https://github.com/libofx/libofx/issues/86

Severity: normal => major

Comment 4 Nicolas Salguero 2022-09-29 09:33:25 CEST
Suggested advisory:
========================

The updated packages fix memory issues in libofx. (rhbz#2127755)

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2127755
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/YP7TQYRM2UPP5R5NKSEGDFKJARD7VN4A/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/KB467JGE4PFVR3LULWPIHJNHW4ORBRRJ/
https://bugzilla.redhat.com/show_bug.cgi?id=2130201
https://github.com/libofx/libofx/issues/86
========================

Updated packages in core/updates_testing:
========================
lib(64)ofx7-0.9.15-2.1.mga8
lib(64)ofx-devel-0.9.15-2.1.mga8
libofx-0.9.15-2.1.mga8

from SRPM:
libofx-0.9.15-2.1.mga8.src.rpm

Status: NEW => ASSIGNED
Version: Cauldron => 8
Assignee: pkg-bugs => qa-bugs
CC: (none) => nicolas.salguero
Whiteboard: MGA8TOO => (none)
Status comment: Patches available from Fedora => (none)
Source RPM: libofx-0.10.7.mga8.src.rpm => libofx-0.9.15-2.mga8.src.rpm

Comment 5 Thomas Andrews 2022-10-12 03:51:22 CEST
No installation issues.

I had hoped to be able to download a document from my bank in OFX format, but they only supply documents in Quicken-related formats. So, I searched the Internet for a sample file and found only one, at https://gist.github.com/jvz/2837829 (I'll include it as an attachment)

urpmq --whatrequires-recursive libofx indicates that Skrooge requires the above library. 

$ skrooge example.ofx seems to import the file without reporting any errors, but in reading the ofx file it appears that part of the information was incorrectly imported. For example, the bank ID number looks correct, as does the account ID, but the account type, "SAVINGS" in the file, appears as "Current" in Skrooge. Other information in the file seems to be missing entirely from Skrooge. Unfortunately, not knowing anything about the format, I can't say whether the errors are in the file, or in Skrooge's importation.

I don't know where to go from here.

CC: (none) => andrewsfarm

Comment 6 Thomas Andrews 2022-10-12 03:52:46 CEST
Created attachment 13419 [details]
sample ofx file
Comment 7 Dave Hodgins 2022-10-12 05:42:39 CEST
Check the prior version to see if it's a regression. If it's not a regression,
ok and validate the update. If it is a regression, assign it back to the
packager.

CC: (none) => davidwhodgins

Comment 8 Thomas Andrews 2022-10-12 13:14:28 CEST
I thought of that myself as I was going to bed last night. I checked, and the file loads the same using the older version. I tend to conclude that it is probably the 11-year-old file that could be in error.

OKing, and validating. Advisory in Comment 4.

CC: (none) => sysadmin-bugs
Whiteboard: (none) => MGA8-64-OK
Keywords: (none) => validated_update

Dave Hodgins 2022-10-13 20:56:28 CEST

Keywords: (none) => advisory

Comment 9 Mageia Robot 2022-10-13 22:06:30 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0368.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.