Bug 33314 - bouncycastle new security issue CVE-2024-30171
Summary: bouncycastle new security issue CVE-2024-30171
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Nicolas Lécureuil
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2024-06-19 10:05 CEST by Nicolas Salguero
Modified: 2024-06-20 21:16 CEST (History)
1 user (show)

See Also:
Source RPM: bouncycastle-1.77-1.mga10.src.rpm
CVE: CVE-2024-30171
Status comment: Fixed upstream in 1.78.1


Attachments

Description Nicolas Salguero 2024-06-19 10:05:32 CEST
openSUSE has issued an advisory on June 18:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/NCEDYUZRBIYFFW6ATWOW33BSWPBY2U52/

The problem is fixed in version 1.78.1.

Mageia 9 is also affected.
Nicolas Salguero 2024-06-19 10:06:07 CEST

Source RPM: (none) => bouncycastle-1.77-1.mga10.src.rpm
CVE: (none) => CVE-2024-30171
Status comment: (none) => Fixed upstream in 1.78.1
Whiteboard: (none) => MGA9TOO

Comment 1 Marja Van Waes 2024-06-20 21:16:27 CEST
Assigning to the registered bouncycastle maintainer

CC: (none) => marja11
Assignee: bugsquad => mageia


Note You need to log in before you can comment on or make changes to this bug.