Bug 31122 - android-tools new security issues CVE-2022-3168 and CVE-2022-20128
Summary: android-tools new security issues CVE-2022-3168 and CVE-2022-20128
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-11-14 18:53 CET by David Walser
Modified: 2024-01-12 10:31 CET (History)
3 users (show)

See Also:
Source RPM: android-tools-10.0.0_r2-3.mga8.src.rpm
CVE:
Status comment: Fixed upstream in 33.0.3p1


Attachments

Description David Walser 2022-11-14 18:53:52 CET
Fedora has issued an advisory today (November 14):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/M323FGLTHUKLZTBSMG34DOHO3KN5RIHV/

The issues are fixed upstream in 33.0.3p1.

Mageia 8 is also affected.
David Walser 2022-11-14 18:54:09 CET

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Fixed upstream in 33.0.3p1

Comment 1 Lewis Smith 2022-11-14 20:14:13 CET
This SRPM has lost its registered maintainer, so have to assign this update globally.

Assignee: bugsquad => pkg-bugs

Comment 2 Morgan Leijström 2022-11-15 16:07:42 CET
Also for this package:

I suggest to at the same time fix
Bug 24139 - Rename fastboot-android into just fastboot

And
Bug 29157 - fastboot-android fail to use mke2fs

Lots of work in
Bug 28860 - Access to your smartphone via ADB (user permissions)

CC: (none) => fri

Comment 3 David Walser 2022-11-15 16:57:03 CET
In other words, this is another package that should be dropped.
Comment 4 Morgan Leijström 2022-11-15 22:48:32 CET
Hold of dropping for a while - 
I stirred the pot and a packager is making a try :)
https://bugs.mageia.org/show_bug.cgi?id=28860#c80
Comment 5 Stig-Ørjan Smelror 2022-11-21 19:51:43 CET
Version 33.0.3p1 pushed to Cauldron

CC: (none) => smelror

Comment 6 David Walser 2022-11-21 23:39:35 CET
Indeed, android-tools-33.0.3p1-1.mga9.src.rpm uploaded on November 11.

Version: Cauldron => 8
Source RPM: android-tools-31.0.3p2-1.mga9.src.rpm => android-tools-10.0.0_r2-3.mga8.src.rpm
Whiteboard: MGA8TOO => (none)

Comment 7 Nicolas Salguero 2024-01-12 10:31:43 CET
Mageia 8 EOL

Status: NEW => RESOLVED
CC: (none) => nicolas.salguero
Resolution: (none) => OLD


Note You need to log in before you can comment on or make changes to this bug.