Bug 34136 - zvbi new security issues CVE-2025-217[3-7]
Summary: zvbi new security issues CVE-2025-217[3-7]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-03-25 13:53 CET by Nicolas Salguero
Modified: 2025-03-31 17:54 CEST (History)
4 users (show)

See Also:
Source RPM: zvbi-0.2.43-1.mga10.src.rpm, zvbi-0.2.35-9.mga9.src.rpm
CVE: CVE-2025-2173, CVE-2025-2174, CVE-2025-2175, CVE-2025-2176, CVE-2025-2177
Status comment: Fixed upstream in 0.2.44, patches available from Ubuntu


Attachments

Description Nicolas Salguero 2025-03-25 13:53:46 CET
Ubuntu has issued an advisory on March 24:
https://ubuntu.com/security/notices/USN-7367-1
Nicolas Salguero 2025-03-25 13:55:46 CET

Source RPM: (none) => zvbi-0.2.43-1.mga10.src.rpm, zvbi-0.2.35-9.mga9.src.rpm
CVE: (none) => CVE-2025-2173, CVE-2025-2174, CVE-2025-2175, CVE-2025-2176, CVE-2025-2177
Status comment: (none) => Fixed upstream in 0.2.44, patches available from Ubuntu
Whiteboard: (none) => MGA9TOO

Comment 1 David GEIGER 2025-03-27 15:20:37 CET
Fixed both Cauldron and mga9!

Whiteboard: MGA9TOO => (none)
Version: Cauldron => 9
CC: (none) => geiger.david68210

Comment 2 David GEIGER 2025-03-27 15:21:58 CET
Assigning to QA,

Packages in 9/Core/Updates_testing:
======================
lib64zvbi-devel-0.2.44-1.mga9
lib64zvbi0-0.2.44-1.mga9
libzvbi-devel-0.2.44-1.mga9
libzvbi0-0.2.44-1.mga9
zvbi-0.2.44-1.mga9

From SRPMS
zvbi-0.2.44-1.mga9.src.rpm

Assignee: bugsquad => qa-bugs

katnatek 2025-03-27 23:44:49 CET

Keywords: (none) => advisory

Comment 3 katnatek 2025-03-28 00:27:13 CET
RH x86_64

installing lib64zvbi0-0.2.44-1.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ##################################################################################################
      1/1: lib64zvbi0            ##################################################################################################
      1/1: removing lib64zvbi0-0.2.35-9.mga9.x86_64
                                 ##################################################################################################

Even when vlc-plugin-common is in the list of packages requiring this I not found evidence of the lib playing a video

Also gstreamer plugins are in the list but play video with gst-play-1.0 not found evidence of the lib

xawtv and motv are out of my common use
Comment 4 Herman Viaene 2025-03-28 10:11:43 CET
MGA9-64 Plasma Wayand on Compaq H000SB.
No installation issues.
Reading from github on zvbi: "The vertical blanking interval (VBI) is an interval in an analog television signal ......"
I wonder who has such beast still avaliable. Further I read about ats- and ntsc-signals, hardly applicable here in Belgium.
If no one else can make some sense of this, I propose to give the OK on, clean install. Over and out.

CC: (none) => herman.viaene

Comment 5 katnatek 2025-03-29 03:04:40 CET
LC_ALL=C urpmi zvbi


installing zvbi-0.2.44-1.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ##################################################################################################
      1/1: zvbi                  ##################################################################################################

zvbi-ntsc-cc --help
CCDecoder 0.13 -- Closed Caption and XDS decoder
Copyright (C) 2003-2007 Mike Baker, Mark K. Kim, Michael H. Schimek
<mschimek@users.sf.net>; Based on code by timecop@japan.co.jp.
This program is licensed under GPL 2 or later. NO WARRANTIES.

Usage: zvbi-ntsc-cc [options]
Options:
-? | -h | --help | --usage  Print this message and exit
-1 ... -4 | --cc1-file ... --cc4-file filename
                            Append caption channel CC1 ... CC4 to this file
-b | --no-webtv             Do not print WebTV links
-c | --cc                   Print Closed Caption (includes WebTV)
-d | --device filename      VBI device [/dev/vbi]
-f | --filter type[,type]*  Select XDS info: all, call, desc, length,
                            network, rating, time, timecode, timezone,
                            title. Multiple -f options accumulate. [all]
-k | --keyword string       Break caption line at this word (broken?).
                            Multiple -k options accumulate.
-l | --channel number       Select caption channel 1 ... 4 [no filter]
-p | --plain-ascii          Print plain ASCII, else insert VT.100 color,
                            italic and underline control codes
-r | --raw line-number      Dump raw VBI data
-s | --sentences            Decode caption by sentences
-v | --verbose              Increase verbosity
-w | --window               Open debugging window (with -r option)
-x | --xds                  Print XDS info
-C | --cc-file filename     Append all caption to this file [stdout]
-R | --semi-raw             Dump semi-raw VBI data (with -r option)
-S | --v4l2-sliced          Capture sliced (not raw) VBI data [raw]
-X | --xds-file filename    Append XDS info to this file [stdout]

zvbi-atsc-cc -h works

zvbi-chains -h
zvbi-chains: unknown option or argument: -h
Usage: zvbi-chains [options ...] command ...
       -dev <path>         : VBI device path (default: any VBI device)
       -debug <level>      : enable debug output: 1=warnings, 2=all
       -help               : this message
       --                  : stop option processing

man zvbid 
zvbid(1)                                                 VBI proxy daemon                                                zvbid(1)

NAME
       zvbid - VBI proxy daemon

SYNOPSIS
       zvbid [ options ]

DESCRIPTION
       zvbid  is a proxy for VBI devices, i.e. it forwards one or more VBI data streams to one or more connected clients and man‐
       ages channel change requests

And more

So look good

Whiteboard: (none) => MGA9-64-OK
CC: (none) => andrewsfarm

Comment 6 Thomas Andrews 2025-03-30 20:30:56 CEST
Validating.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update

Comment 7 Mageia Robot 2025-03-31 17:54:53 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0121.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.