Bug 31505 - opusfile new security issue CVE-2022-47021
Summary: opusfile new security issue CVE-2022-47021
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-02-03 01:56 CET by David Walser
Modified: 2023-02-07 01:09 CET (History)
4 users (show)

See Also:
Source RPM: opusfile-0.12-3.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2023-02-03 01:56:32 CET
Fedora has issued an advisory today (February 2):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/4LIKBLOE433RA44YTYUZLED4IOWJG5DV/

Mageia 8 is also affected.
David Walser 2023-02-03 01:56:49 CET

Status comment: (none) => Patches available from upstream and Fedora
Whiteboard: (none) => MGA8TOO

Comment 1 David GEIGER 2023-02-04 16:10:00 CET
Done for both mga8 and Cauldron!

CC: (none) => geiger.david68210

Comment 2 David Walser 2023-02-04 16:18:03 CET
lib64opusfile0-0.12-1.1.mga8
lib64opusfile-devel-0.12-1.1.mga8

from opusfile-0.12-1.1.mga8.src.rpm

Assignee: bugsquad => qa-bugs
Status comment: Patches available from upstream and Fedora => (none)
Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)

Comment 3 Thomas Andrews 2023-02-06 00:58:38 CET
Tested in a VirtualBox mga8-64 Plasma guest. No installation issues.

urpmq --whatrequires lib64opusfile0 produces a relatively short list, with one of the results a game called "Taisei." 

I used "strace -o opus.txt taipei" and played the game, getting killed rather quickly, then examined the resulting opus.txt file. The search found one call to "/lib64/libopusfile.so.0" 

Going to call this OK. Validating.

Keywords: (none) => validated_update
Whiteboard: (none) => MGA8-64-OK
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2023-02-06 21:22:09 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 4 Mageia Robot 2023-02-07 01:09:06 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0042.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.