Bug 31214 - libetpan new security issue CVE-2022-4121
Summary: libetpan new security issue CVE-2022-4121
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-12-02 17:42 CET by David Walser
Modified: 2022-12-17 19:49 CET (History)
5 users (show)

See Also:
Source RPM: libetpan-1.9.4-4.mga8.src.rpm
CVE: CVE-2022-4121
Status comment:


Attachments

Description David Walser 2022-12-02 17:42:00 CET
Fedora has issued an advisory today (December 2):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DO2JJCQZGGB7E7RSP775ARXODFQLBYXL/

Mageia 8 is also affected.
David Walser 2022-12-02 17:42:14 CET

Status comment: (none) => Patch available from Fedora
Whiteboard: (none) => MGA8TOO

Comment 1 Lewis Smith 2022-12-02 20:36:32 CET
Assigning this globally as there is no packager in view for libetpan.

Assignee: bugsquad => pkg-bugs

Comment 2 Nicolas Salguero 2022-12-05 10:54:41 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c. (CVE-2022-4121)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4121
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DO2JJCQZGGB7E7RSP775ARXODFQLBYXL/
========================

Updated packages in core/updates_testing:
========================
lib(64)etpan20-1.9.4-4.1.mga8
lib(64)etpan-devel-1.9.4-4.1.mga8

from SRPM:
libetpan-1.9.4-4.1.mga8.src.rpm

Source RPM: libetpan-1.9.4-5.mga9.src.rpm => libetpan-1.9.4-4.mga8.src.rpm
Status comment: Patch available from Fedora => (none)
Status: NEW => ASSIGNED
Assignee: pkg-bugs => qa-bugs
Version: Cauldron => 8
CC: (none) => nicolas.salguero
Whiteboard: MGA8TOO => (none)
CVE: (none) => CVE-2022-4121

Comment 3 Herman Viaene 2022-12-16 15:37:15 CET
MGA8-64 MATE on Acer Aspire 5253
No installation issues
Ref bug 27168 testing by using claws-mail to send ans receive mails without and with attachaments, all OK.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 4 Thomas Andrews 2022-12-16 19:51:11 CET
Validating. Advisory in Comment 2.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2022-12-17 18:18:15 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 5 Mageia Robot 2022-12-17 19:49:31 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0470.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.