| Summary: | php-pear-CAS new security issues fixed upstream in 1.3.5 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | lewyssmith, mageia, marja11, mhrambo3501, sysadmin-bugs |
| Version: | 5 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | has_procedure MGA5-64-OK advisory | ||
| Source RPM: | php-pear-CAS-1.3.4-4.mga6.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2017-04-23 00:23:19 CEST
David Walser
2017-04-23 00:23:25 CEST
Whiteboard:
(none) =>
MGA5TOO Assigning to all packagers collectively, since there is no registered maintainer for this package. Assignee:
bugsquad =>
pkg-bugs
Nicolas Lécureuil
2017-04-24 11:56:59 CEST
Version:
Cauldron =>
5 Updated package uploaded for Mageia 5. Advisory: ======================== Updated php-pear-CAS package fixes security vulnerability: It was discovered that php-pear-CAS contained a possible authentication bypass in validateCAS20. References: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/2THFM2BPR5YGBE42CTAPCAUVZ77UDLYF/ https://github.com/apereo/phpCAS/issues/228 ======================== Updated packages in core/updates_testing: ======================== php-pear-CAS-1.3.5-1.mga5.noarch.rpm from php-pear-CAS-1.3.5-1.mga5.src.rpm Testing procedure: https://bugs.mageia.org/show_bug.cgi?id=10136#c3 Assignee:
pkg-bugs =>
qa-bugs Testing M5-64 using Moodle - the only application directly using this package. "This package is a PEAR installable library for using a Central Authentication Service." Updated the pkg from : php-pear-CAS-1.3.3-4.mga5 to : php-pear-CAS-1.3.5-1.mga5 Trying Moodle (long installed & used for its own updates): http://localhost/moodle Well, I was able to log in as administrator and add a couple of things. Moodle still works - within my complete lack of know-how of it. Oking; and since this is M5 only, validating as well. This has hung around for weeks. CC:
(none) =>
lewyssmith, sysadmin-bugs Advisory done from comment 2; but it lacks a CVE. Whiteboard:
has_procedure MGA5-64-OK =>
has_procedure MGA5-64-OK advisory An update for this issue has been pushed to the Mageia Updates repository. http://advisories.mageia.org/MGASA-2017-0293.html Status:
NEW =>
RESOLVED |