Bug 33993 - libtasn1 new security issue CVE-2024-12133
Summary: libtasn1 new security issue CVE-2024-12133
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-02-07 10:26 CET by Nicolas Salguero
Modified: 2025-02-08 03:23 CET (History)
3 users (show)

See Also:
Source RPM: libtasn1-4.19.0-1.mga9.src.rpm
CVE: CVE-2024-12133
Status comment: Fixed upstream in 4.20.0 and patches available from upstream


Attachments

Nicolas Salguero 2025-02-07 10:26:46 CET

Status comment: (none) => Fixed upstream in 4.20.0 and patches available from upstream
CVE: (none) => CVE-2024-12133
Source RPM: (none) => libtasn1-4.19.0-1.mga9.src.rpm

Comment 1 David GEIGER 2025-02-07 14:29:40 CET
Assigning to QA,

Packages in 9/Core/Updates_testing:
======================
libtasn1-devel-4.20.0-1.mga9
libtasn1_6-4.20.0-1.mga9
lib64tasn1-devel-4.20.0-1.mga9
lib64tasn1_6-4.20.0-1.mga9
libtasn1-tools-4.20.0-1.mga9

From SRPMS
libtasn1-4.20.0-1.mga9.src.rpm

Assignee: bugsquad => qa-bugs
CC: (none) => geiger.david68210

katnatek 2025-02-07 19:32:11 CET

Keywords: (none) => advisory

Comment 2 katnatek 2025-02-07 22:46:31 CET
RH x86_64

installing lib64tasn1_6-4.20.0-1.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ##################################################################################################
      1/1: lib64tasn1_6          ##################################################################################################
      1/1: removing lib64tasn1_6-4.19.0-1.mga9.x86_64
                                 ##################################################################################################


strace blender shows
openat(AT_FDCWD, "/lib64/libtasn1.so.6", O_RDONLY|O_CLOEXEC) = 3

The application starts without issues

CC: (none) => andrewsfarm
Whiteboard: (none) => MGA9-64-OK

Comment 3 Thomas Andrews 2025-02-08 01:50:24 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 4 Mageia Robot 2025-02-08 03:23:43 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0043.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.