Bug 20968

Summary: systemd new security issue CVE-2017-9217
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Colin Guthrie <mageia>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: mageia, marja11
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: systemd-230-10.mga6.src.rpm CVE: CVE-2017-9217
Status comment:

Description David Walser 2017-05-29 14:25:43 CEST
Fedora has issued an advisory on May 28:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/YXDUSK6OUHURC7O3QKNN3FUCEPB3SKIN/

The RedHat bug contains a link to the upstream commit that fixed the issue:
https://bugzilla.redhat.com/show_bug.cgi?id=1455493

Mageia 5 is also affected.
David Walser 2017-05-29 14:26:01 CEST

Whiteboard: (none) => MGA5TOO

Marja Van Waes 2017-05-29 20:56:41 CEST

CC: (none) => marja11
Assignee: bugsquad => mageia

Comment 1 Nicolas Lécureuil 2017-06-02 10:55:41 CEST
Fixed in cauldron

CVE: (none) => CVE-2017-9217
CC: (none) => mageia
Version: Cauldron => 5
Whiteboard: MGA5TOO => (none)

Comment 2 Nicolas Lécureuil 2017-06-02 10:59:48 CEST
there is no dns_packet_is_reply_for function in systemd 217 so mga5 is not affected ( please reopen if i am wrong )

Resolution: (none) => FIXED
Status: NEW => RESOLVED

Comment 3 David Walser 2017-06-02 11:53:40 CEST
Indeed, RedHat later posted that the issue was introduced in systemd 225.

Version: 5 => Cauldron