Bugzilla – Bug 823113
VUL-0: libkdcraw: CVE-2013-2126: double-free issue in embed copy of libraw
Last modified: 2013-07-10 11:22:27 UTC
The libkdcraw has an embedded copy of libraw. A security incident for libraw was started in bnc#822665.
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (823113) was mentioned in https://build.opensuse.org/request/show/181646 Maintenance /
I have issued a maintenance update for 12.2 to include the fix in libkdcraw. The fix for libkdcraw in 12.3 will be delivered together with the KDE 4.10.5 maintenance update (which is ready in KDE:Release:410, but not yet released). Factory and KDE:Distro:Factory will not require the fix, as that there the libraw inside libkdcraw has been updated to the 0.15.2 release.
There is already a submit: 181646, what about this? It seems to miss the patch filename as required by OBS guildelines, so will be dropped anyway.
Euh ?? libkdcraw is following KDE release versions, so the version in 12.2 is 4.8,5 and the one in 12.3 is currently 4.10.3. That is why I submitted the initial request 181646 as that this covers ONLY the 12.2 libkdcraw with the version 4.8.5. The update for 12.3 will come together with the update to KDE 4.10.5. What is wrong with the patch filename ?? I never heard about a specific naming convention for patches. But if you are going to drop the submit request, then also close this bugreport.
The name is not wrong, it just needs be mentioned. :) The opensuse review team requires to mention the patchfilename in the .changes entries these days for Factory and Maintenance submissions. so basically just include "bnc823113.diff" in the changes entry line.
Thanks Marcus, That explains it :-) I thought that I mentioned the patch, but the only thing I included in the changes file was the bug reference. Apologies for this and I just submitted a new update. You can drop the old SR.
The new request is SR#181753. Please only accept for openSUSE_12.2:Update
12.2 and 12.3 are in one request, I am not sure I could only accept 12.2 out of it.
procedure: - accept request as usual - osc rdelete openSUSE:Maintenance:1834 libkdcraw.openSUSE_12.3_Update -m ok - osc meta prj -e openSUSE:Maintenance:1834 .. delete thje 12.3 repos (did that already ;)
openSUSE-SU-2013:1168-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 823113 CVE References: CVE-2013-2126 Sources used: openSUSE 12.2 (src): libkdcraw-4.8.5-2.8.1
released