| Summary: | owasp-esapi-java new security issue CVE-2013-5679 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | sysadmin-bugs |
| Version: | 4 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/629679/ | ||
| Whiteboard: | has_procedure advisory mga4-64-ok mga4-32-ok | ||
| Source RPM: | owasp-esapi-java-2.0.1-10.mga5.src.rpm | CVE: | |
| Status comment: | |||
| Bug Depends on: | |||
| Bug Blocks: | 15051 | ||
|
Description
David Walser
2015-02-10 14:52:01 CET
David Walser
2015-02-10 14:53:19 CET
Blocks:
(none) =>
15051 Updated package uploaded for Mageia 4. Just test that the package installs cleanly. Advisory: ======================== Updated owasp-esapi-java packages fix security vulnerability: The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against authenticity in the default configuration, involving a null MAC and a zero MAC length (CVE-2013-5679). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5679 https://lists.fedoraproject.org/pipermail/package-announce/2015-January/148081.html ======================== Updated packages in core/updates_testing: ======================== owasp-esapi-java-2.1.0-1.mga4 owasp-esapi-java-javadoc-2.1.0-1.mga4 owasp-esapi-java-doc-2.1.0-1.mga4 from owasp-esapi-java-2.1.0-1.mga4.src.rpm CC:
geiger.david68210, pterjan =>
(none) Testing complete mga4 64 As with most java packages, just verified it updates cleanly. Comes with 270 dependencies. Advisory uploaded. Whiteboard:
has_procedure =>
has_procedure advisory mga4-64-ok Confirmed that it installs fine on Mageia 4 i586 as well. Validating. Please push to core/updates. Thanks. Keywords:
(none) =>
validated_update An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGASA-2015-0064.html Status:
NEW =>
RESOLVED |