Bug 25743

Summary: networkmanager possible new security issue CVE-2018-1000135
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Jani Välimaa <jani.valimaa>
Status: RESOLVED INVALID QA Contact: Sec team <security>
Severity: normal    
Priority: Normal    
Version: 7   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: networkmanager-1.18.2-1.mga7.src.rpm CVE:
Status comment:

Description David Walser 2019-11-25 21:53:01 CET
openSUSE has issued an advisory on June 3:
https://lists.opensuse.org/opensuse-updates/2019-06/msg00011.html

I've found info saying it was never addressed upstream, but Ubuntu's info page had a link to an upstream commit, and SUSE said some fix had been backported.  RH/Fedora had said it wasn't affected because of a config option that I don't see in Fedora's current package (and we don't have our own local config like they do), so I'm not sure if it affects us (still) or not.
Comment 1 Lewis Smith 2019-11-26 20:22:34 CET
Assigning to wally as the registered maintainer for this package.

Assignee: bugsquad => jani.valimaa

Comment 2 Jani Välimaa 2019-11-26 21:03:51 CET
IINM this was fixed in 1.12.0 and backported later to 1.10.14. In mga7 we have 1.18.2.
Comment 3 David Walser 2019-11-26 21:10:36 CET
Thanks.

Resolution: (none) => INVALID
Status: NEW => RESOLVED