Bug 31650 - xfig new security issue CVE-2021-40241
Summary: xfig new security issue CVE-2021-40241
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-03-09 17:39 CET by David Walser
Modified: 2023-03-18 23:18 CET (History)
5 users (show)

See Also:
Source RPM: xfig-3.2.8b-1.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2023-03-09 17:39:44 CET
Debian-LTS has issued an advisory on March 5:
https://www.debian.org/lts/security/2023/dla-3353

Mageia 8 is also affected.
David Walser 2023-03-09 17:39:56 CET

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Patch available from Debian

Comment 1 Lewis Smith 2023-03-09 20:07:27 CET
Xfig has no particular maintainer, so assigning this update globally.

Assignee: bugsquad => pkg-bugs

Comment 2 David GEIGER 2023-03-10 06:08:49 CET
Patch added for mga8!

But CVE-2021-40241 is already fixed in 3.2.8b release for Cauldron.

CC: (none) => geiger.david68210

Comment 3 David Walser 2023-03-10 12:22:52 CET
xfig-3.2.7b-1.1.mga8

from xfig-3.2.7b-1.1.mga8.src.rpm

Status comment: Patch available from Debian => (none)
Version: Cauldron => 8
Assignee: pkg-bugs => qa-bugs
Whiteboard: MGA8TOO => (none)

Comment 4 Herman Viaene 2023-03-12 16:58:57 CET
MGA8-64 MATE on Acer Aspire 5253
No installation issues.
I could open xfig, draw some shapes, saved the file and re-opened it. All my scriblings were there.
So it seems to work. For my own curiosity I tried to open/import this file into some other program. Tried LODraw and Inkscape, but all failed. But this is probably due to my inexperience in such matters.
So giving the OK based on the fact that drawing works OK and it can re-open its own files.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA8-64-OK

Comment 5 Thomas Andrews 2023-03-12 22:58:36 CET
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2023-03-14 20:53:15 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 6 Mageia Robot 2023-03-18 23:18:33 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0101.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.