Activity log for bug #1954722

Date Who What changed Old value New value Message
2021-12-14 01:06:35 Ghada Khalil bug added bug
2021-12-14 01:07:03 Ghada Khalil information type Public Public Security
2021-12-14 01:07:17 Ghada Khalil tags stx.6.0 stx.7.0 stx.security
2021-12-14 01:07:21 Ghada Khalil starlingx: importance Undecided High
2021-12-14 01:07:23 Ghada Khalil starlingx: status New Triaged
2021-12-14 01:07:57 Ghada Khalil starlingx: assignee Yue Tao (wrytao)
2021-12-14 01:12:50 Ghada Khalil description CVE-2018-25011: libwebp: heap-based buffer overflow in PutLE16() CVE-2020-36328: libwebp: heap-based buffer overflow in WebPDecode*Into functions CVE-2020-36329: libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c Score: cve_id status cvss2Score av ac au ai CVE-2018-25011 fixed 7.5 N L N P CVE-2020-36328 fixed 7.5 N L N P CVE-2020-36329 fixed 7.5 N L N P Description: CVE-2018-25011: A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow was found in PutLE16(). The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CVE-2020-36328: A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CVE-2020-36329: A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. References: https://nvd.nist.gov/vuln/detail/CVE-2018-25011 https://nvd.nist.gov/vuln/detail/CVE-2020-36328 https://nvd.nist.gov/vuln/detail/CVE-2020-36329 https://access.redhat.com/errata/RHSA-2021:2260 Required Package Versions: libwebp-0.3.0-10.el7_9.x86_64.rpm Packages: libwebp Found during December 2021 CVE Scan CVE-2018-25011: libwebp: heap-based buffer overflow in PutLE16() CVE-2020-36328: libwebp: heap-based buffer overflow in WebPDecode*Into functions CVE-2020-36329: libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c Score: cve_id status cvss2Score av ac au ai CVE-2018-25011 fixed 7.5 N L N P CVE-2020-36328 fixed 7.5 N L N P CVE-2020-36329 fixed 7.5 N L N P Description: CVE-2018-25011: A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow was found in PutLE16(). The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CVE-2020-36328: A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CVE-2020-36329: A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. References: https://nvd.nist.gov/vuln/detail/CVE-2018-25011 https://nvd.nist.gov/vuln/detail/CVE-2020-36328 https://nvd.nist.gov/vuln/detail/CVE-2020-36329 https://access.redhat.com/errata/RHSA-2021:2260 http://mirror.centos.org/centos/7/updates/x86_64/Packages/libwebp-0.3.0-10.el7_9.x86_64.rpm Required Package Versions: libwebp-0.3.0-10.el7_9.x86_64.rpm Packages: libwebp Found during December 2021 CVE Scan
2021-12-14 21:06:59 Ghada Khalil starlingx: assignee Yue Tao (wrytao) Joe Slater (jslater0wind)
2021-12-16 21:08:29 Ghada Khalil starlingx: importance High Medium
2021-12-22 18:17:40 OpenStack Infra starlingx: status Triaged In Progress
2021-12-29 14:43:27 OpenStack Infra starlingx: status In Progress Fix Released
2021-12-29 14:43:28 OpenStack Infra cve linked 2018-25011
2021-12-29 14:43:28 OpenStack Infra cve linked 2020-36328
2021-12-29 14:43:28 OpenStack Infra cve linked 2020-36329
2022-01-04 23:18:06 Ghada Khalil tags stx.6.0 stx.7.0 stx.security stx.6.0 stx.7.0 stx.cherrypickneeded stx.security
2022-01-06 15:31:23 Ghada Khalil tags stx.6.0 stx.7.0 stx.cherrypickneeded stx.security in-r-stx60 stx.6.0 stx.7.0 stx.cherrypickneeded stx.security
2022-01-06 15:31:34 Ghada Khalil tags in-r-stx60 stx.6.0 stx.7.0 stx.cherrypickneeded stx.security in-r-stx60 stx.6.0 stx.7.0 stx.security