Bug 31985 - c-ares new security issues CVE-2023-32067, CVE-2023-31147, CVE-2023-31130, CVE-2023-31124
Summary: c-ares new security issues CVE-2023-32067, CVE-2023-31147, CVE-2023-31130, C...
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-06-01 17:36 CEST by David Walser
Modified: 2024-01-12 10:53 CET (History)
2 users (show)

See Also:
Source RPM: c-ares-1.19.0-1.mga9.src.rpm
CVE:
Status comment: Fixed upstream in 1.19.1


Attachments

David Walser 2023-06-01 17:36:27 CEST

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Fixed upstream in 1.19.1

Comment 1 Lewis Smith 2023-06-01 21:19:36 CEST
This SRPM is done by various people, so assigning this update globally.
CC'ing MikeR who put up version 1.19.0.

Assignee: bugsquad => pkg-bugs
CC: (none) => mhrambo3501

Comment 2 Nicolas Salguero 2023-06-08 10:32:54 CEST
Hi,

Freeze move requested for c-ares-1.19.1-1.mga9.

Best regards,

Nico.

Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)
CC: (none) => nicolas.salguero

Comment 3 David Walser 2023-06-14 21:56:26 CEST
RedHat has issued an advisory for CVE-2023-32067 today (June 14):
https://access.redhat.com/errata/RHSA-2023:3584
Comment 4 David Walser 2023-06-15 23:37:27 CEST
Debian has issued an advisory for CVE-2023-31130 and CVE-2023-32067 on June 7:
https://www.debian.org/security/2023/dsa-5419
Comment 5 David Walser 2023-06-20 15:06:08 CEST
Ubuntu has issued an advisory for CVE-2023-31130, CVE-2023-32067 on June 14:
https://ubuntu.com/security/notices/USN-6164-1
Comment 6 Nicolas Salguero 2024-01-12 10:53:18 CET
Mageia 8 EOL

Status: NEW => RESOLVED
Resolution: (none) => OLD


Note You need to log in before you can comment on or make changes to this bug.