| Summary: | axis new security issue CVE-2018-8032 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | andrewsfarm, geiger.david68210, herman.viaene, mageia, marja11, sysadmin-bugs, tmb |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA6-32-OK | ||
| Source RPM: | axis-1.4-34.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2018-08-29 20:54:12 CEST
Assigning to the java stack maintainers, CC'ing the registered maintainer and a committer. CC:
(none) =>
geiger.david68210, mageia, marja11 openSUSE has issued an advisory for this on October 18: https://lists.opensuse.org/opensuse-updates/2018-10/msg00103.html axis on Cauldron can be removed nothing required it anymore now! Thanks! Added to task-obsolete in Cauldron (not pushed yet). Version:
Cauldron =>
6 Fixed for mga6! Advisory: ======================== Updated axis packages fix security vulnerability: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services (CVE-2018-8032). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8032 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/Q5PSL3445FAECTG4YYE7GBG6QIR75LAK/ ======================== Updated packages in core/updates_testing: ======================== axis-1.4-32.1.mga6 axis-javadoc-1.4-32.1.mga6 axis-manual-1.4-32.1.mga6 from axis-1.4-32.1.mga6.src.rpm Assignee:
java =>
qa-bugs MGA6-32 MATE on IBM Thinkpad R50e No installation issues. Ref to bug 14103 Comment 3 clean install is sufficient. OK with me. Whiteboard:
(none) =>
MGA6-32-OK Validating. Advisory in comment 6. Keywords:
(none) =>
validated_update
Thomas Backlund
2018-11-03 11:47:17 CET
CC:
(none) =>
tmb An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2018-0431.html Resolution:
(none) =>
FIXED |