Bug 22774

Summary: ceph new security issue CVE-2018-7262
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Nicolas Lécureuil <mageia>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: critical    
Priority: Normal CC: mhrambo3501
Version: 6   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: ceph-10.2.9-1.mga7.src.rpm CVE:
Status comment: Fixed upstream in 12.2.4
Bug Depends on: 23312    
Bug Blocks: 22202    

Description David Walser 2018-03-15 14:41:38 CET
Fedora has issued an advisory on March 14:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/74VI6EPZ6LD2O4JJXJBTYQ4U4VUO2ZDO/

The issue is fixed upstream in 12.2.4.

Mageia 6 is also affected.
Comment 1 David Walser 2018-03-15 14:42:45 CET
The security issues for this package are starting to pile up (also Bug 21975 and Bug 22202).  Please fix them ASAP.

Status comment: (none) => Fixed upstream in 12.2.4
Whiteboard: (none) => MGA6TOO
Blocks: (none) => 22202

Comment 2 David Walser 2018-06-07 23:20:27 CEST
openSUSE has issued an advisory for this on May 30:
https://lists.opensuse.org/opensuse-updates/2018-05/msg00139.html
David Walser 2018-07-16 21:03:48 CEST

Depends on: (none) => 23312

David Walser 2018-11-21 00:39:02 CET

Whiteboard: MGA6TOO => (none)
Version: Cauldron => 6

Comment 3 Mike Rambo 2019-11-06 13:22:57 CET
Mageia 6 is EOL.

CC: (none) => mrambo
Status: NEW => RESOLVED
Resolution: (none) => OLD