Bug 9198 - pixman new security issue CVE-2013-1591
Summary: pixman new security issue CVE-2013-1591
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 2
Hardware: i586 Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/540269/
Whiteboard: MGA2-64-OK MGA2-32-OK
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2013-02-27 19:20 CET by David Walser
Modified: 2013-03-01 22:25 CET (History)
3 users (show)

See Also:
Source RPM: pixman-0.24.4-1.mga2.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2013-02-27 19:20:00 CET
Fedora has issued an advisory on February 14:
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/099334.html

Cauldron is not affected as it was fixed upstream.

Patched package uploaded for Mageia 2.

Advisory:
========================

Updated pixman packages fix security vulnerability:

Stack-based buffer overflow in libpixman has unspecified impact and attack vectors (CVE-2013-1591).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1591
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/099334.html
========================

Updated packages in core/updates_testing:
========================
libpixman1_0-0.24.4-1.1.mga2
libpixman-devel-0.24.4-1.1.mga2

from pixman-0.24.4-1.1.mga2.src.rpm

Reproducible: 

Steps to Reproduce:
Comment 1 Dave Hodgins 2013-02-28 05:12:04 CET
Testing complete on Mageia 2 i586 and x86_64.

No poc, so just testing that firefox is working ok, with strace
confirming the library is being used.

Could someone from the sysadmin team push the srpm
pixman-0.24.4-1.1.mga2.src.rpm
from Mageia 2 Core Updates Testing to Core Updates.

Advisory: Updated pixman packages fix security vulnerability:

Stack-based buffer overflow in libpixman has unspecified impact and attack vectors (CVE-2013-1591).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1591
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/099334.html

https://bugs.mageia.org/show_bug.cgi?id=9198

Keywords: (none) => validated_update
CC: (none) => davidwhodgins, sysadmin-bugs
Whiteboard: (none) => MGA2-64-OK MGA2-32-OK

Comment 2 Thomas Backlund 2013-03-01 22:25:27 CET
Update pushed:
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0077

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.