Bug 9791

Summary: libpgf security vulnerability (CVE-2015-6673)
Product: [ROSA-based products] ROSA Fresh Reporter: Zombie Ryushu <zombie.ryushu>
Component: Packages from MainAssignee: ROSA Linux Bugs <bugs>
Status: VERIFIED FIXED QA Contact: ROSA Linux Bugs <bugs>
Severity: normal    
Priority: Normal CC: alzim, andrey.bondrov, denis.silakov, mc2374, pastordidi, v.potapov
Version: AllFlags: v.potapov: qa_verified+
andrey.bondrov: published+
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: https://advisories.mageia.org/MGASA-2019-0014.html
Whiteboard:
Platform: --- ROSA Vulnerability identifier: CVE-2015-6673
RPM Package: libpgf-6.14.12-3.src.rpm ISO-related:
Bad POT generating: Upstream:

Description Zombie Ryushu 2019-03-05 06:24:26 MSK
Use-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32
(CVE-2015-6673).
Comment 1 Andrey Bondrov 2019-08-27 08:41:06 MSK
Advisory: "Fix CVE-2015-6673 in libpgf"

https://abf.rosalinux.ru/build_lists/3090818
https://abf.rosalinux.ru/build_lists/3090819

P.S. Thanx for reporting security issues :-)
Comment 2 Dmitry Postnikov 2019-08-27 12:39:37 MSK
The update is sent to expanded testing
***************************************
Comment 3 Vladimir Potapov 2019-08-27 12:58:37 MSK
libpgf-6.14.12-6
https://abf.rosalinux.ru/build_lists/3090818
https://abf.rosalinux.ru/build_lists/3090819
****************************** Advisory ******************************
Fix CVE-2015-6673 in libpgf
**********************************************************************
QA Verified