Bug 31247 - woff2 possible new double free security issue
Summary: woff2 possible new double free security issue
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Jean-Pierre Aubin
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-12-08 15:35 CET by David Walser
Modified: 2023-07-02 14:35 CEST (History)
1 user (show)

See Also:
Source RPM: woff2-1.0.2-5.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-12-08 15:35:14 CET
Fedora has issued an advisory today (December 8):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/UKXGAHTBXYEQGJAG6MQPCH7QNBP5SY7S/

This is in the original woff, but woff2 should be checked to see if it's affected too.  If so, Mageia 8 is also affected.
Comment 1 Lewis Smith 2022-12-08 21:20:47 CET
Jean-pierre (pol4n) has updated this package recently, so assigning to you.
If this is not right, please re-assign it to pkg-bugs.

Assignee: bugsquad => jean-pierre

Comment 2 David GEIGER 2023-07-02 07:51:25 CEST
I checked wolff2 source code and I confirm that wolff2 is NOT affected by this double free security issue!

CC: (none) => geiger.david68210

Comment 3 David Walser 2023-07-02 14:35:41 CEST
Thanks!

Resolution: (none) => INVALID
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.