| Summary: | axis new security issue CVE-2014-3596 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | critical | ||
| Priority: | Normal | CC: | herman.viaene, mageia, olchal, sysadmin-bugs |
| Version: | 4 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/611992/ | ||
| Whiteboard: | advisory MGA4-32-OK MGA4-64-OK | ||
| Source RPM: | axis-1.4-24.mga4.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2014-09-16 19:04:21 CEST
David Walser
2014-09-16 19:04:31 CEST
Whiteboard:
(none) =>
MGA4TOO, MGA3TOO Dropped from cauldron. Whiteboard:
MGA4TOO, MGA3TOO =>
(none) Probably on its way back to Cauldron, but I added the upstream patch in Mageia 4 and Cauldron SVN (replacing the CVE-2012-5784 patch that it supercedes). Fedora has yet to address this. Patched package uploaded for Mageia 4. Verifying that the updated packages install cleanly is sufficient for testing this update. Advisory: ======================== Updated axis packages fixes security vulnerability: It was discovered that Axis incorrectly extracted the host name from an X.509 certificate subject's Common Name (CN) field. A man-in-the-middle attacker could use this flaw to spoof an SSL server using a specially crafted X.509 certificate (CVE-2014-3596). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3596 https://rhn.redhat.com/errata/RHSA-2014-1193.html ======================== Updated package in core/updates_testing: ======================== axis-1.4-24.1.mga4 axis-javadoc-1.4-24.1.mga4 axis-manual-1.4-24.1.mga4 from axis-1.4-24.1.mga4.src.rpm Assignee:
dmorganec =>
qa-bugs Testing on Mageia4x32 real hardware. First installed current packages : axis-1.4-24.mga4 axis-javadoc-1.4-24.mga4 axis-manual-1.4-24.mga4 Then updated testing packages : axis-1.4-24.1.mga4 axis-javadoc-1.4-24.1.mga4 axis-manual-1.4-24.1.mga4 No problem detected through installation. CC:
(none) =>
olchal MGA4-64 on HP Probook 6555b No installation problems. CC:
(none) =>
herman.viaene Validating. Advisory uploaded. Please push to updates Thanks Whiteboard:
MGA4-32-OK MGA4-64-OK =>
advisory MGA4-32-OK MGA4-64-OK An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGASA-2014-0549.html Resolution:
(none) =>
FIXED |