Bug 9198 - pixman new security issue CVE-2013-1591
: pixman new security issue CVE-2013-1591
Status: RESOLVED FIXED
Product: Mageia
Classification: Unclassified
Component: Security
: 2
: i586 Linux
: Normal Severity: major
: ---
Assigned To: QA Team
: Sec team
: http://lwn.net/Vulnerabilities/540269/
: MGA2-64-OK MGA2-32-OK
: validated_update
:
:
  Show dependency treegraph
 
Reported: 2013-02-27 19:20 CET by David Walser
Modified: 2013-03-01 22:25 CET (History)
3 users (show)

See Also:
Source RPM: pixman-0.24.4-1.mga2.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2013-02-27 19:20:00 CET
Fedora has issued an advisory on February 14:
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/099334.html

Cauldron is not affected as it was fixed upstream.

Patched package uploaded for Mageia 2.

Advisory:
========================

Updated pixman packages fix security vulnerability:

Stack-based buffer overflow in libpixman has unspecified impact and attack vectors (CVE-2013-1591).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1591
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/099334.html
========================

Updated packages in core/updates_testing:
========================
libpixman1_0-0.24.4-1.1.mga2
libpixman-devel-0.24.4-1.1.mga2

from pixman-0.24.4-1.1.mga2.src.rpm

Reproducible: 

Steps to Reproduce:
Comment 1 Dave Hodgins 2013-02-28 05:12:04 CET
Testing complete on Mageia 2 i586 and x86_64.

No poc, so just testing that firefox is working ok, with strace
confirming the library is being used.

Could someone from the sysadmin team push the srpm
pixman-0.24.4-1.1.mga2.src.rpm
from Mageia 2 Core Updates Testing to Core Updates.

Advisory: Updated pixman packages fix security vulnerability:

Stack-based buffer overflow in libpixman has unspecified impact and attack vectors (CVE-2013-1591).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1591
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/099334.html

https://bugs.mageia.org/show_bug.cgi?id=9198
Comment 2 Thomas Backlund 2013-03-01 22:25:27 CET
Update pushed:
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0077

Note You need to log in before you can comment on or make changes to this bug.