Bug 32272 - erofs-utils new security issues CVE-2023-3355[12]
Summary: erofs-utils new security issues CVE-2023-3355[12]
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Thierry Vignaud
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO, MGA8TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2023-09-11 14:09 CEST by Nicolas Salguero
Modified: 2023-09-12 21:13 CEST (History)
1 user (show)

See Also:
Source RPM: erofs-utils-1.5-1.mga9.src.rpm
CVE:
Status comment: Fixed in v1.6.3


Attachments

Description Nicolas Salguero 2023-09-11 14:09:05 CEST
Fedora has issued an advisory on September 7:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FHOIRL6XH5NYR3LYI3KP5DE4SDSQWR7W/

Mageia 8 and 9 are also affected.
Nicolas Salguero 2023-09-11 14:09:38 CEST

Source RPM: (none) => erofs-utils-1.5-1.mga9.src.rpm
CC: (none) => nicolas.salguero
Whiteboard: (none) => MGA9TOO, MGA8TOO

Comment 1 Lewis Smith 2023-09-12 21:13:18 CEST
Version : 1.6.3 "- Backport patches for CVE-2023-33551 and CVE-2023-33552."

Thierry is the clear committer for this pkg, so assigning to you.

Assignee: bugsquad => thierry.vignaud
Status comment: (none) => Fixed in v1.6.3


Note You need to log in before you can comment on or make changes to this bug.