Bug 33170 - traceroute new security issue CVE-2023-46316
Summary: traceroute new security issue CVE-2023-46316
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-05-02 11:24 CEST by Nicolas Salguero
Modified: 2024-05-09 04:41 CEST (History)
3 users (show)

See Also:
Source RPM: traceroute-2.1.2-1.mga9.src.rpm
CVE: CVE-2023-46316
Status comment:


Attachments

Description Nicolas Salguero 2024-05-02 11:24:48 CEST
RedHat has issued an advisory on April 30:
https://lwn.net/Articles/971676/

The problem is fixed in version 2.1.3.

Mageia 9 is also affected.
Nicolas Salguero 2024-05-02 11:25:19 CEST

Status comment: (none) => Fixed upstream in 2.1.3
Whiteboard: (none) => MGA9TOO
CVE: (none) => CVE-2023-46316
Source RPM: (none) => traceroute-2.1.2-2.mga10.src.rpm

Comment 1 Nicolas Salguero 2024-05-02 14:45:18 CEST
Suggested advisory:
========================

The updated package fixes a security vulnerability:

In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines. (CVE-2023-46316)

References:
https://lwn.net/Articles/971676/
========================

Updated package in core/updates_testing:
========================
traceroute-2.1.3-1.mga9

from SRPM:
traceroute-2.1.3-1.mga9.src.rpm

Status: NEW => ASSIGNED
Version: Cauldron => 9
Whiteboard: MGA9TOO => (none)
Status comment: Fixed upstream in 2.1.3 => (none)
Source RPM: traceroute-2.1.2-2.mga10.src.rpm => traceroute-2.1.2-1.mga9.src.rpm
Assignee: bugsquad => qa-bugs

PC LX 2024-05-02 18:01:00 CEST

CC: (none) => mageia

katnatek 2024-05-02 19:32:51 CEST

Keywords: (none) => advisory

Comment 2 katnatek 2024-05-04 04:59:08 CEST
RH mageia 9 x86_64

Output of traceroute mageia.org before and after the update looks quite similar (some few fluctuations in times are expected)

Not additional test information in previous round

So I think is OK
katnatek 2024-05-04 04:59:20 CEST

CC: (none) => andrewsfarm

katnatek 2024-05-04 04:59:32 CEST

Whiteboard: (none) => MGA9-64-OK

Comment 3 Thomas Andrews 2024-05-04 13:20:02 CEST
Validating.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update

Comment 4 Mageia Robot 2024-05-09 04:41:59 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0168.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.