Bug 33929 - raptor2 new security issue CVE-2024-57823
Summary: raptor2 new security issue CVE-2024-57823
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-01-16 15:51 CET by Nicolas Salguero
Modified: 2025-01-20 21:02 CET (History)
4 users (show)

See Also:
Source RPM: raptor2-2.0.16-3.mga10.src.rpm, raptor2-2.0.15-23.mga9.src.rpm
CVE: CVE-2024-57823
Status comment: Patch available from openSUSE


Attachments

Description Nicolas Salguero 2025-01-16 15:51:13 CET
openSUSE has issued an advisory on January 15:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/7S7ZVXAGSBLZGFFVSEHSDXQND2DNAKY2/
Nicolas Salguero 2025-01-16 15:51:49 CET

Whiteboard: (none) => MGA9TOO
CVE: (none) => CVE-2024-57823
Status comment: (none) => Patch available from openSUSE
Source RPM: (none) => raptor2-2.0.16-3.mga10.src.rpm, raptor2-2.0.15-23.mga9.src.rpm

Comment 1 David GEIGER 2025-01-17 10:26:01 CET
Fixed both mga9 and Cauldron!

CC: (none) => geiger.david68210
Version: Cauldron => 9
Whiteboard: MGA9TOO => (none)

Comment 2 David GEIGER 2025-01-17 10:27:44 CET
Assigning to QA,

Packages in 9/Core/Updates_testing:
======================
libraptor2-devel-2.0.15-23.1.mga9
libraptor2_0-2.0.15-23.1.mga9
lib64raptor2-devel-2.0.15-23.1.mga9
lib64raptor2_0-2.0.15-23.1.mga9
raptor2-2.0.15-23.1.mga9

From SRPMS
raptor2-2.0.15-23.1.mga9.src.rpm

Assignee: bugsquad => qa-bugs

Comment 3 Herman Viaene 2025-01-17 15:50:58 CET
MGA9-64 Plasma Wayland on Compaq H000SB
No installation issues.
Ref bug 27605, picking up test files attached there.
$ rapper rss_8_1.rdf
rapper: Parsing URI file:///home/tester9/Documents/rss_8_1.rdf with parser rdfxml
rapper: Serializing with serializer ntriples
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://www.w3.org/1999/02/22-rdf-syntax-ns#type> <http://purl.org/rss/1.0/channel> .
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://purl.org/rss/1.0/title> "Meerkat" .
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://purl.org/rss/1.0/link> "http://meerkat.oreillynet.com" .
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://purl.org/rss/1.0/description> "Meerkat: An Open Wire Service" .
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://purl.org/dc/elements/1.1/publisher> "The O'Reilly Network" .
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://purl.org/dc/elements/1.1/creator> "Rael Dornfest (mailto:rael@oreilly.com)" .
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://purl.org/dc/elements/1.1/rights> "Copyright \u00A9 2000 O'Reilly & Associates, Inc." .
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://purl.org/dc/elements/1.1/date> "2000-01-01T12:00+00:00" .
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://purl.org/rss/1.0/modules/syndication/updatePeriod> "hourly" .
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://purl.org/rss/1.0/modules/syndication/updateFrequency> "2" .
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://purl.org/rss/1.0/modules/syndication/updateBase> "2000-01-01T12:00+00:00" .
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://purl.org/rss/1.0/image> <http://meerkat.oreillynet.com/icons/meerkat-powered.jpg> .
_:genid1 <http://www.w3.org/1999/02/22-rdf-syntax-ns#type> <http://www.w3.org/1999/02/22-rdf-syntax-ns#Seq> .
_:genid1 <http://www.w3.org/1999/02/22-rdf-syntax-ns#_1> <http://c.moreover.com/click/here.pl?r123> .
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://purl.org/rss/1.0/items> _:genid1 .
<http://meerkat.oreillynet.com/?_fl=rss1.0> <http://purl.org/rss/1.0/textinput> <http://meerkat.oreillynet.com> .
<http://meerkat.oreillynet.com/icons/meerkat-powered.jpg> <http://www.w3.org/1999/02/22-rdf-syntax-ns#type> <http://purl.org/rss/1.0/image> .
<http://meerkat.oreillynet.com/icons/meerkat-powered.jpg> <http://purl.org/rss/1.0/title> "Meerkat Powered!" .
<http://meerkat.oreillynet.com/icons/meerkat-powered.jpg> <http://purl.org/rss/1.0/url> "http://meerkat.oreillynet.com/icons/meerkat-powered.jpg" .
<http://meerkat.oreillynet.com/icons/meerkat-powered.jpg> <http://purl.org/rss/1.0/link> "http://meerkat.oreillynet.com" .
<http://c.moreover.com/click/here.pl?r123> <http://www.w3.org/1999/02/22-rdf-syntax-ns#type> <http://purl.org/rss/1.0/item> .
<http://c.moreover.com/click/here.pl?r123> <http://purl.org/rss/1.0/title> "XML: A Disruptive Technology" .
<http://c.moreover.com/click/here.pl?r123> <http://purl.org/rss/1.0/link> "http://c.moreover.com/click/here.pl?r123" .
<http://c.moreover.com/click/here.pl?r123> <http://purl.org/dc/elements/1.1/description> "\n      XML is placing increasingly heavy loads on the existing technical\n      infrastructure of the Internet.\n    " .
<http://c.moreover.com/click/here.pl?r123> <http://purl.org/dc/elements/1.1/publisher> "The O'Reilly Network" .
<http://c.moreover.com/click/here.pl?r123> <http://purl.org/dc/elements/1.1/creator> "Simon St.Laurent (mailto:simonstl@simonstl.com)" .
<http://c.moreover.com/click/here.pl?r123> <http://purl.org/dc/elements/1.1/rights> "Copyright \u00A9 2000 O'Reilly & Associates, Inc." .
<http://c.moreover.com/click/here.pl?r123> <http://purl.org/dc/elements/1.1/subject> "XML" .
<http://c.moreover.com/click/here.pl?r123> <http://purl.org/rss/1.0/modules/company/name> "XML.com" .
<http://c.moreover.com/click/here.pl?r123> <http://purl.org/rss/1.0/modules/company/market> "NASDAQ" .
<http://c.moreover.com/click/here.pl?r123> <http://purl.org/rss/1.0/modules/company/symbol> "XML" .
<http://meerkat.oreillynet.com> <http://www.w3.org/1999/02/22-rdf-syntax-ns#type> <http://purl.org/rss/1.0/textinput> .
<http://meerkat.oreillynet.com> <http://purl.org/rss/1.0/title> "Search Meerkat" .
<http://meerkat.oreillynet.com> <http://purl.org/rss/1.0/description> "Search Meerkat's RSS Database..." .
<http://meerkat.oreillynet.com> <http://purl.org/rss/1.0/name> "s" .
<http://meerkat.oreillynet.com> <http://purl.org/rss/1.0/link> "http://meerkat.oreillynet.com/" .
<http://meerkat.oreillynet.com> <http://purl.org/rss/1.0/modules/textinput/function> "search" .
<http://meerkat.oreillynet.com> <http://purl.org/rss/1.0/modules/textinput/inputType> "regex" .
rapper: Parsing returned 38 triples
Looks good.

Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene

Comment 4 Thomas Andrews 2025-01-20 14:37:31 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

katnatek 2025-01-20 20:03:38 CET

Keywords: (none) => advisory

Comment 5 Mageia Robot 2025-01-20 21:02:36 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0018.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.