| Summary: | koji new security issue CVE-2019-17109 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, sysadmin-bugs |
| Version: | 7 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA7-64-OK | ||
| Source RPM: | koji-1.17.0-2.mga8.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2019-12-26 04:48:22 CET
David Walser
2019-12-26 04:48:32 CET
Whiteboard:
(none) =>
MGA7TOO
David Walser
2020-01-14 17:38:33 CET
Status comment:
(none) =>
Fixed upstream in 1.18.1 koji-1.23.0-1.mga8 uploaded for Cauldron by Neal. Whiteboard:
MGA7TOO =>
(none) I've uploaded a fixed version to updates-testing for Mageia 7. Suggested advisory: ======================== Updated koji packages fix security vulnerabilities: Koji through 1.17.0 allows remote Directory Traversal, with resultant Privilege Escalation. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17109 https://bugzilla.redhat.com/show_bug.cgi?id=1768882 ======================== Updated packages in core/updates_testing: ======================== koji-1.17.1-1.mga7 python3-koji-1.17.1-1.mga7 python3-koji-cli-plugins-1.17.1-1.mga7 koji-hub-1.17.1-1.mga7 koji-hub-plugins-1.17.1-1.mga7 koji-builder-1.17.1-1.mga7 koji-vm-1.17.1-1.mga7 koji-utils-1.17.1-1.mga7 koji-web-1.17.1-1.mga7 Source RPMs: koji-1.17.1-1.mga7.src.rpm Assignee:
ngompa13 =>
qa-bugs
David Walser
2021-03-14 15:59:48 CET
Status comment:
Fixed upstream in 1.17.1 =>
(none) Searched Bugzilla for previous updates, and found Bug 24421, where koji had been OKed and validated based on a clean install over the old packages. I went to install all of the packages on a real hardware test install, but discovered that the total install, including dependencies, would involve 128 packages. Not wanting all those extra packages left after the test, I switched to a VirtualBox mga7-64 Plasma guest. No installation issues when installing the current mga7 koji and dependencies, and all packages listed in Comment 2 updated cleanly. Sending this one on its way. Validating. Advisory in Comment 2. Keywords:
(none) =>
validated_update
Thomas Backlund
2021-03-21 10:43:09 CET
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0147.html Resolution:
(none) =>
FIXED |