Bug 32016 - gpac security issues CVE-2023-3012 CVE-2023-3291
Summary: gpac security issues CVE-2023-3012 CVE-2023-3291
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-06-15 23:24 CEST by David Walser
Modified: 2024-02-09 02:35 CET (History)
4 users (show)

See Also:
Source RPM: gpac-2.2.1-1.mga9.tainted.src.rpm
CVE: CVE-2023-3012 CVE-2023-3291
Status comment:


Attachments

Description David Walser 2023-06-15 23:24:45 CEST Comment hidden (obsolete)
David Walser 2023-06-15 23:27:40 CEST

Whiteboard: (none) => MGA8TOO

Comment 1 David GEIGER 2023-06-16 05:15:44 CEST Comment hidden (obsolete)

CC: (none) => geiger.david68210

Comment 2 Lewis Smith 2023-06-16 20:30:10 CEST Comment hidden (obsolete)

Assignee: bugsquad => geiger.david68210
CC: geiger.david68210 => (none)

Comment 3 David GEIGER 2023-06-17 07:03:45 CEST Comment hidden (obsolete)

Version: Cauldron => 8
Source RPM: gpac-2.2.0-1.mga9.tainted.src.rpm => gpac-1.0.1-1.1.mga8.tainted.src.rpm
Whiteboard: MGA8TOO => (none)

Comment 4 David Walser 2023-07-17 21:52:31 CEST
Debian has issued an advisory on July 14:
https://www.debian.org/security/2023/dsa-5452

It adds CVE-2023-3012 and CVE-2023-3291, which will be fixed upstream in 2.2.2.

Version: 8 => Cauldron
Source RPM: gpac-1.0.1-1.1.mga8.tainted.src.rpm => gpac-2.2.1-1.mga9.tainted.src.rpm
Whiteboard: (none) => MGA8TOO

Comment 5 David GEIGER 2024-02-03 11:27:38 CET
Done for both Cauldron and mga9!


Assigning to QA,

Packages in 9/Tainted/Updates_testing:
=======================
gpac-2.2.1-1.1.mga9.tainted
lib64gpac-devel-2.2.1-1.1.mga9.tainted
lib64gpac12-2.2.1-1.1.mga9.tainted
libgpac-devel-2.2.1-1.1.mga9.tainted
libgpac12-2.2.1-1.1.mga9.tainted

From SRPMS:
gpac-2.2.1-1.1.mga9.tainted.src.rpm

Whiteboard: MGA8TOO => (none)
Version: Cauldron => 9
Assignee: geiger.david68210 => qa-bugs

Comment 6 katnatek 2024-02-03 19:20:21 CET
Tested on real hardware mageia 9 x86_64

Install current version

gpac 
[core] Creating default credential key in /home/katnatek/.gpac/creds.key, use -cred=PATH/TO_FILE to overwrite
Refreshing all options registry, this may take some time ... done
Nothing to do, check usage "gpac -h"
gpac - GPAC command line filter engine - version 2.2.1-revrelease
(c) 2000-2022 Telecom Paris distributed under LGPL v2.1+ - http://gpac.io

Please cite our work in your research:
        GPAC Filters: https://doi.org/10.1145/3339825.3394929
        GPAC: https://doi.org/10.1145/1291233.1291452

Update without issues

gpac 
Nothing to do, check usage "gpac -h"
gpac - GPAC command line filter engine - version 2.2.1-revrelease
(c) 2000-2022 Telecom Paris distributed under LGPL v2.1+ - http://gpac.io

Please cite our work in your research:
        GPAC Filters: https://doi.org/10.1145/3339825.3394929
        GPAC: https://doi.org/10.1145/1291233.1291452

Some test that need to be done?
Marja Van Waes 2024-02-03 21:18:21 CET

CC: (none) => marja11
Summary: gpac several new security issues => gpac security issues CVE-2023-3012 CVE-2023-3291
CVE: (none) => CVE-2023-3012 CVE-2023-3291

Marja Van Waes 2024-02-03 21:21:44 CET

Keywords: (none) => advisory

Comment 7 Brian Rockwell 2024-02-06 23:18:02 CET
MGA9-64, Gnome

The following 4 packages are going to be installed:

- gpac-2.2.1-1.1.mga9.tainted.x86_64
- lib64faad2-2.10.0-2.mga9.tainted.x86_64
- lib64gpac12-2.2.1-1.1.mga9.tainted.x86_64
- lib64xvidcore4-1.3.7-2.mga9.tainted.x86_64

12MB of additional disk space will be used


--

I tested the different basic commands using a m4v video.

gpac -h
gpac -gui
gpac -vbench *.*
gpac -mplay *.*
gpac -play *.*
gpac -info *.m*


It worked as expected

CC: (none) => brtians1
Whiteboard: (none) => MGA9-64-OK

Comment 8 Thomas Andrews 2024-02-07 14:15:33 CET
Thanks, guys. Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 9 Mageia Robot 2024-02-09 02:35:27 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0027.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.