Bug 33783 - neochat new security issue CVE-2024-52868
Summary: neochat new security issue CVE-2024-52868
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-11-20 10:08 CET by Nicolas Salguero
Modified: 2025-03-24 19:05 CET (History)
1 user (show)

See Also:
Source RPM: neochat-23.04.3-1.mga9.src.rpm
CVE: CVE-2024-52868
Status comment: Fixed upstream in 24.08.2


Attachments

Description Nicolas Salguero 2024-11-20 10:08:51 CET
That problem was announced here:
https://kde.org/info/security/advisory-20241120-1.txt
Nicolas Salguero 2024-11-20 10:09:21 CET

Source RPM: (none) => neochat-23.04.3-1.mga9.src.rpm
CVE: (none) => CVE-2024-52868
Status comment: (none) => Fixed upstream in 24.08.2
Whiteboard: (none) => MGA9TOO

Comment 1 David GEIGER 2024-11-20 20:02:25 CET
Cauldron is fixed with latest 24.11.80 release!

Version: Cauldron => 9
CC: (none) => geiger.david68210
Whiteboard: MGA9TOO => (none)

katnatek 2024-11-21 03:08:29 CET

See Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=33366

Comment 2 Lewis Smith 2024-11-21 13:23:59 CET
And we have had version 24.08.2 since Oct 13 2024...

Assigning globally for the M9 update.

Assignee: bugsquad => pkg-bugs

Comment 3 saundra jcain 2025-03-24 09:11:01 CET Comment hidden (spam)

CC: (none) => bellegrobbins

Nicolas Salguero 2025-03-24 09:17:21 CET

CC: bellegrobbins => (none)

Comment 4 katnatek 2025-03-24 18:35:13 CET
BuildRequires for neochat 24.08.3 are highest than available in mageia 9

https://github.com/KDE/neochat/blob/v24.08.3/CMakeLists.txt

(In reply to David GEIGER from comment #1)
> Cauldron is fixed with latest 24.11.80 release!

Is possible have 25.03.80 ?
Comment 5 David GEIGER 2025-03-24 19:05:32 CET
Yes when I planned to update all kde-apps stack!

Note You need to log in before you can comment on or make changes to this bug.