Bug 22924

Summary: glusterfs new security issue CVE-2018-1088
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: All Packagers <pkg-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: critical    
Priority: Normal CC: geiger.david68210, mageia, marja11
Version: 6   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: glusterfs-3.7.9-1.mga6.src.rpm CVE:
Status comment:

Description David Walser 2018-04-18 17:39:43 CEST
RedHat has issued an advisory today (April 18):
https://access.redhat.com/errata/RHSA-2018:1136
Comment 1 Marja Van Waes 2018-04-18 21:46:07 CEST
Assigning to all packagers collectively, since there is no registered maintainer for this package.

CC: (none) => marja11
Assignee: bugsquad => pkg-bugs

Comment 2 Marja Van Waes 2018-04-18 21:51:27 CEST
It was obsoleted 11 months ago

http://svnweb.mageia.org/packages/obsolete/glusterfs/releases/3.7.9/

Resolution: (none) => INVALID
Status: NEW => RESOLVED

Comment 3 David Walser 2018-04-19 13:37:00 CEST
Not correctly.  The package "python-gluster" was not obsoleted.  It was entered into task-obsolete incorrectly as "python-glusterfs"

Since we're updating task-obsolete for the Plasma update, let's fix it there.

Status: RESOLVED => REOPENED
Resolution: INVALID => (none)
CC: (none) => geiger.david68210, mageia

Comment 4 David GEIGER 2018-04-19 14:03:18 CEST
Done!
Comment 5 David Walser 2018-04-19 14:31:33 CEST
Thanks!

Resolution: (none) => FIXED
Status: REOPENED => RESOLVED