Bug 31040 - jhead new security issues CVE-2021-34055 and CVE-2022-41751
Summary: jhead new security issues CVE-2021-34055 and CVE-2022-41751
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: Jani Välimaa
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-10-27 14:49 CEST by David Walser
Modified: 2024-01-12 10:29 CET (History)
2 users (show)

See Also:
Source RPM: jhead-3.06.0.1-2.mga9.src.rpm
CVE:
Status comment: Patches available from Fedora and openSUSE


Attachments

Description David Walser 2022-10-27 14:49:15 CEST
Fedora has issued an advisory on October 26:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TAVB3ZX7E5ULEXESU5NXZIAHY6CVGCHB/

Mageia 8 is also affected.
David Walser 2022-10-27 14:49:25 CEST

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Patches available from Fedora

Comment 1 Lewis Smith 2022-10-29 22:22:06 CEST
Assigning to Jani, registered maintainer.

Assignee: bugsquad => jani.valimaa

Comment 2 David Walser 2022-11-01 13:49:14 CET
openSUSE has issued an advisory for this on October 31:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SYRTRE3WPQSFOZ2DYZDAYDI3Q7I53AB6/
Comment 3 David Walser 2022-11-15 15:03:02 CET
openSUSE has issued an advisory on November 14:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VFW7LPBWACIK5T4XBHVQEUEXUGR6W2Q7/

Mageia 8 is also affected.

Summary: jhead new security issue CVE-2022-41751 => jhead new security issues CVE-2021-34055 and CVE-2022-41751
Status comment: Patches available from Fedora => Patches available from Fedora and openSUSE

Comment 4 David Walser 2022-12-06 17:32:47 CET
Debian has issued an advisory for this on December 4:
https://www.debian.org/security/2022/dsa-5294
Comment 5 David Walser 2023-06-20 14:40:42 CEST
Ubuntu has issued an advisory for this on May 25:
https://ubuntu.com/security/notices/USN-6108-1

Freeze move requested for jhead 3.08 in Cauldron, which should fix these.
Comment 6 David GEIGER 2023-06-27 02:55:53 CEST
Fixed on cauldron!

Version: Cauldron => 8
CC: (none) => geiger.david68210
Whiteboard: MGA8TOO => (none)

Comment 7 Nicolas Salguero 2024-01-12 10:29:38 CET
Mageia 8 EOL

CC: (none) => nicolas.salguero
Status: NEW => RESOLVED
Resolution: (none) => OLD


Note You need to log in before you can comment on or make changes to this bug.