Bug 34013 - ark new security issue CVE-2024-57966
Summary: ark new security issue CVE-2024-57966
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-02-12 14:12 CET by Nicolas Salguero
Modified: 2025-02-13 20:09 CET (History)
5 users (show)

See Also:
Source RPM: ark-23.04.3-1.mga9.src.rpm
CVE: CVE-2024-57966
Status comment: Patch available from upstream


Attachments

Description Nicolas Salguero 2025-02-12 14:12:52 CET
Upstream has issued an advisory on February 7:
https://kde.org/info/security/advisory-20250207-1.txt

Fix: https://github.com/KDE/ark/commit/fe518d81b338941e0bf1c5ce5e75a9ab6de4bb58
Nicolas Salguero 2025-02-12 14:13:23 CET

Source RPM: (none) => ark-23.04.3-1.mga9.src.rpm
Status comment: (none) => Patches available from upstream
CVE: (none) => CVE-2024-57966

Nicolas Salguero 2025-02-12 14:13:28 CET

Status comment: Patches available from upstream => Patch available from upstream

Comment 1 David GEIGER 2025-02-12 19:26:32 CET
Assigning to QA,

Packages in 9/Core/Updates_testing:
======================
ark-23.04.3-1.1.mga9
ark-handbook-23.04.3-1.1.mga9.noarch.rpm
libkerfuffle23-23.04.3-1.1.mga9
lib64kerfuffle23-23.04.3-1.1.mga9

From SRPMS
ark-23.04.3-1.1.mga9.src.rpm

Assignee: bugsquad => qa-bugs
CC: (none) => geiger.david68210

katnatek 2025-02-12 19:33:27 CET

Keywords: (none) => advisory

Comment 2 katnatek 2025-02-12 23:35:02 CET
RH x86_64

installing ark-23.04.3-1.1.mga9.x86_64.rpm ark-handbook-23.04.3-1.1.mga9.noarch.rpm lib64kerfuffle23-23.04.3-1.1.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ##################################################################################################
      1/3: lib64kerfuffle23      ##################################################################################################
      2/3: ark-handbook          ##################################################################################################
      3/3: ark                   ##################################################################################################
      1/3: removing ark-23.04.3-1.mga9.x86_64
                                 ##################################################################################################
      2/3: removing ark-handbook-23.04.3-1.mga9.noarch
                                 ##################################################################################################
      3/3: removing lib64kerfuffle23-23.04.3-1.mga9.x86_64
                                 ##################################################################################################
writing /var/lib/rpm/installed-through-deps.list

Test extraction from previous created files,including zip, rpm, tar.[gz, bz2) all OK
PC LX 2025-02-13 00:59:34 CET

CC: (none) => mageia

Comment 3 Herman Viaene 2025-02-13 15:37:38 CET
MGA9-64 Plasma Wayland on Compaq H000SB
No installation issues
Ref bug 27214 for testing
$ cd Documents/
[tester9@mach3 Documents]$ ls
dcmtk.txt    Frans-Bruynseelspad.pdf  Mageia-9-netinstall-x86_64.iso  RSS_1.0.tar.Z  rss_5.3_1.rdf  rss_8_1.rdf  soup.txt           testtexstudio.tex
firefox.exe  libxml/                  php/                            rss_4.1_1.rdf  rss_7_1.rdf    ruby/        testtexstudio.log  volkstuintjes/
[tester9@mach3 Documents]$ tar cvf tartest.tar.gz *
dcmtk.txt
firefox.exe
Frans-Bruynseelspad.pdf
libxml/
libxml/testdata.xml
libxml/testxml.py
php/
php/one.png
php/create-png.php
etc......

In dolphin move the created tar file to myhome/tmp and extracted tar file info tartest folder. All files present and correct.
Good enough for me.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA9-64-OK

Comment 4 Thomas Andrews 2025-02-13 17:02:54 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 5 Mageia Robot 2025-02-13 20:09:55 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0061.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.