MGASA-2018-0399

Source
https://advisories.mageia.org/MGASA-2018-0399.html
Import Source
https://advisories.mageia.org/MGASA-2018-0399.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0399
Related
Published
2018-10-19T18:00:37Z
Modified
2018-10-20T13:46:28Z
Summary
Updated calibre packages fix security vulnerability
Details

Updated calibre package fixes security vulnerability:

gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call (CVE-2018-7889).

The python-html5-parser package is a new dependency for the updated calibre package and has been included with this update.

References
Credits

Affected packages

Mageia:6 / calibre

Package

Name
calibre
Purl
pkg:rpm/mageia/calibre?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.27.1-2.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / python-html5-parser

Package

Name
python-html5-parser
Purl
pkg:rpm/mageia/python-html5-parser?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.4-1.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / python-lxml

Package

Name
python-lxml
Purl
pkg:rpm/mageia/python-lxml?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.0-1.1.mga6

Ecosystem specific

{
    "section": "core"
}