Bug 23445

Summary: ldb new security issue CVE-2018-1140
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Bruno Cornec <bruno>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: bgmilne, bruno, mageia, mageia, marja11
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: ldb-1.3.2-1.mga7.src.rpm CVE:
Status comment:

Description David Walser 2018-08-14 23:21:09 CEST
Samba has issued an advisory today (August 14):
https://www.samba.org/samba/security/CVE-2018-1140.html

The issue is fixed upstream in 1.3.5 and 1.4.1.
Comment 1 Marja Van Waes 2018-08-16 12:29:14 CEST
Assigning to all packagers collectively, since there is no registered maintainer for this package.

CC'ing some committers.

Assignee: bugsquad => pkg-bugs
CC: (none) => bgmilne, mageia, mageia, marja11

Comment 2 Bruno Cornec 2018-10-26 03:02:43 CEST
ldb-1.3.5-1.mga7 uploaded in cauldron

Resolution: (none) => FIXED
Status: NEW => RESOLVED
CC: (none) => bruno

Comment 3 David Walser 2018-10-26 03:05:00 CEST
As the comment in the SPEC file says, samba and sssd need to be rebuilt when this package is updated.

Status: RESOLVED => REOPENED
Resolution: FIXED => (none)

Comment 4 David Walser 2018-10-27 14:33:10 CEST
I see you've updated samba to 4.9.1 (thanks) which takes care of that one.  sssd should *not* be updated to 2.0.0.  1.13.x is the current LTM branch, and the 2.0.0 release notes say that 1.16.x might become one, so we should stay on one of those branches.
Comment 5 Bruno Cornec 2018-10-27 16:22:39 CEST
uploaded the following packages:
tdb-1.3.16-1.mga7
talloc-2.1.14-1.mga7
ldb-1.4.2-1.mga7
samba-4.9.1-1.mga7
sssd-1.13.4-16.mga7
Comment 6 Bruno Cornec 2018-10-27 16:23:26 CEST
I kept sssd 1.13 ;-)

Assignee: pkg-bugs => qa-bugs
Status: REOPENED => ASSIGNED

David Walser 2018-10-27 17:16:33 CEST

Assignee: qa-bugs => bruno

Comment 7 David Walser 2018-10-27 17:16:57 CEST
Perfect.

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED