Bug 13341

Summary: varnish new security issue CVE-2013-0345
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Mageia Bug Squad <bugsquad>
Status: RESOLVED WONTFIX QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: mageia, oe
Version: Cauldron   
Target Milestone: ---   
Hardware: i586   
OS: Linux   
URL: http://lwn.net/Vulnerabilities/597472/
Whiteboard:
Source RPM: varnish-3.0.3-16.mga5.src.rpm CVE:
Status comment:

Description David Walser 2014-05-07 22:47:49 CEST
Fedora has issued an advisory on December 28:
https://lists.fedoraproject.org/pipermail/package-announce/2014-May/132654.html

I'm not sure I agree with this CVE.  In the case of Mageia, we are "affected" as the package ships the directory with 755 permissions, but I would think that anyone that *cares* about such would be running in msec secure mode, which would change it to 700.  I'm open to other opinions.

Reproducible: 

Steps to Reproduce:
David Walser 2014-05-07 22:48:01 CEST

CC: (none) => mageia

Comment 1 Oden Eriksson 2014-05-08 09:56:44 CEST
Last year there were a lot of related CVEs that I just ignored.

CC: (none) => oe

Comment 2 David Walser 2014-05-08 15:03:06 CEST
Thanks Oden.  I probably did too.  I'll close this as WONTFIX.

Status: NEW => RESOLVED
Resolution: (none) => WONTFIX