Bug 30963 - libosip2 new security issue CVE-2022-41550
Summary: libosip2 new security issue CVE-2022-41550
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-10-14 19:38 CEST by David Walser
Modified: 2022-10-24 00:50 CEST (History)
6 users (show)

See Also:
Source RPM: libosip2-5.0.0-4.mga8.src.rpm
CVE: CVE-2022-41550
Status comment:


Attachments

Description David Walser 2022-10-14 19:38:38 CEST
openSUSE has issued an advisory on October 13:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HNIPYSSVD2PSQBQN44WSUXHISIIAWJFS/

Mageia 8 is also affected.
David Walser 2022-10-14 19:38:56 CEST

CC: (none) => mageia
Status comment: (none) => Patch available from openSUSE
Whiteboard: (none) => MGA8TOO

Comment 1 Lewis Smith 2022-10-16 19:28:42 CEST
In the absence of an individual packager for this SRPM, assigning globally.

Assignee: bugsquad => pkg-bugs

Comment 2 Nicolas Salguero 2022-10-17 09:56:59 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header. (CVE-2022-41550)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41550
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HNIPYSSVD2PSQBQN44WSUXHISIIAWJFS/
========================

Updated packages in core/updates_testing:
========================
lib(64)osip2_12-5.0.0-4.1.mga8
lib(64)osip2-devel-5.0.0-4.1.mga8

from SRPM:
libosip2-5.0.0-4.1.mga8.src.rpm

Whiteboard: MGA8TOO => (none)
Status: NEW => ASSIGNED
Assignee: pkg-bugs => qa-bugs
CC: (none) => nicolas.salguero
Status comment: Patch available from openSUSE => (none)
Version: Cauldron => 8
CVE: (none) => CVE-2022-41550

Nicolas Salguero 2022-10-17 09:57:16 CEST

Source RPM: libosip2-5.0.0-5.mga9.src.rpm => libosip2-5.0.0-4.mga8.src.rpm

Comment 3 Herman Viaene 2022-10-20 13:44:27 CEST
MGA8-64 MATE on Acer Aspire 5253
No installation issues.
Ref bug 20758 and on the observation that nothing seems impacted negatively, OK on clean install.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 4 Thomas Andrews 2022-10-20 20:48:25 CEST
Validating. Advisory in Comment 2.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2022-10-23 23:46:49 CEST

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 5 Mageia Robot 2022-10-24 00:50:02 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0389.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.