Bug 4066 - tuxguitar missing update for CVE-2010-3385 (insecure library loading vulnerability)
Summary: tuxguitar missing update for CVE-2010-3385 (insecure library loading vulnerab...
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: José Jorge
QA Contact:
URL:
Whiteboard:
Keywords: Triaged
Depends on:
Blocks:
 
Reported: 2012-01-08 00:16 CET by David Walser
Modified: 2012-01-09 10:40 CET (History)
0 users

See Also:
Source RPM: tuxguitar-1.2-6.mga1.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2012-01-08 00:16:18 CET
This was fixed in Mandriva 2010.2 (contrib) updates on October 15, 2010.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3385
https://bugzilla.redhat.com/show_bug.cgi?id=638396
Comment 1 Manuel Hiebel 2012-01-08 12:15:25 CET
Hi, thanks for reporting this bug.
Assigned to the package maintainer.

(Please set the status to 'assigned' if you are working on it)

Keywords: (none) => Triaged
Assignee: bugsquad => lists.jjorge
Source RPM: /tuxguitar-1.2-6.mga1.src.rpm => tuxguitar-1.2-6.mga1.src.rpm

Comment 2 José Jorge 2012-01-09 10:40:42 CET
As far as I can see, our import of mandriva tuxguitar package was done after this CVE was fixed.

http://svn.mandriva.com/viewvc/packages/cooker/tuxguitar/current/SOURCES/tuxguitar-build-fedora.xml?r1=510936&r2=585777

Status: NEW => RESOLVED
Resolution: (none) => INVALID


Note You need to log in before you can comment on or make changes to this bug.