Bug 33409 - gtk+2.0 and gtk+3.0 new security issue CVE-2024-6655
Summary: gtk+2.0 and gtk+3.0 new security issue CVE-2024-6655
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2024-07-17 15:40 CEST by Nicolas Salguero
Modified: 2024-07-18 09:11 CEST (History)
0 users

See Also:
Source RPM: gtk+3.0-3.24.43-1.mga10.src.rpm, gtk+2.0-2.24.33-5.mga9.src.rpm
CVE: CVE-2024-6655
Status comment: Patches available from Ubuntu


Attachments

Description Nicolas Salguero 2024-07-17 15:40:58 CEST
Ubuntu has issued an advisory on July 16:
https://ubuntu.com/security/notices/USN-6899-1

Mageia 9 is also affected.
Nicolas Salguero 2024-07-17 15:41:31 CEST

Whiteboard: (none) => MGA9TOO
Source RPM: (none) => gtk+3.0-3.24.43-1.mga10.src.rpm, gtk+2.0-2.24.33-5.mga9.src.rpm
Status comment: (none) => Patches available from Ubuntu
CVE: (none) => CVE-2024-6655

Comment 1 Lewis Smith 2024-07-17 20:38:20 CEST
I cannot find the patches. This is the best thing I did find:
gtk+2.0_2.24.33.orig.tar.xz
https://launchpad.net/ubuntu/+archive/primary/+sourcefiles/gtk+2.0/2.24.33-4ubuntu1.1/gtk+2.0_2.24.33.orig.tar.xz

but the equivalent link for GTK+3 went nowhere.
They are Ubuntu files anyway.

Assigning globally.

Assignee: bugsquad => pkg-bugs

Comment 2 Nicolas Salguero 2024-07-18 09:11:31 CEST
Hi,

In Debian and Ubuntu, the "orig" tarballs are the upstream ones.

The patches from Debian or Ubuntu are in the "debian" tarballs:

https://launchpad.net/ubuntu/+archive/primary/+sourcefiles/gtk+2.0/2.24.33-4ubuntu1.1/gtk+2.0_2.24.33-4ubuntu1.1.debian.tar.xz

https://launchpad.net/ubuntu/+archive/primary/+sourcefiles/gtk+3.0/3.24.41-4ubuntu1.1/gtk+3.0_3.24.41-4ubuntu1.1.debian.tar.xz

Best regards,

Nico.

Note You need to log in before you can comment on or make changes to this bug.