Bug 28536

Summary: 389-ds-base new security issue CVE-2020-35518
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: All Packagers <pkg-bugs>
Status: RESOLVED INVALID QA Contact: Sec team <security>
Severity: major    
Priority: Normal CC: mageia, nicolas.salguero, ouaurelien
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: 389-ds-base-1.4.0.26-8.mga8.src.rpm CVE: CVE-2020-35518
Status comment:
Bug Depends on: 30001    
Bug Blocks:    

Description David Walser 2021-03-06 00:05:23 CET
Fedora has issued an advisory on March 3:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/Y2XAPBAAYVGYPC2QTEVMUSVI5KVZJ7LF/

The issue is fixed upstream in 1.4.3.19.

Mageia 7 and Mageia 8 are also affected.
David Walser 2021-03-06 00:05:34 CET

Whiteboard: (none) => MGA8TOO, MGA7TOO

Comment 2 Aurelien Oudelet 2021-03-06 11:53:40 CET
Hi, thanks for reporting this.
As there is no maintainer for this package I added Nicolas S. committers in CC.

(Please set the status to 'assigned' if you are working on it)

CC: (none) => nicolas.salguero, ouaurelien
Assignee: bugsquad => pkg-bugs
CVE: (none) => CVE-2020-35518

Comment 3 Nicolas Lécureuil 2021-03-08 23:18:18 CET
mga7 and 8 and current cauldron are not affected, the code faulty code have been added later ( see https://github.com/389ds/389-ds-base/issues/2535 )

Whiteboard: MGA8TOO, MGA7TOO => (none)
CC: (none) => mageia

Comment 4 David Walser 2021-04-18 00:34:27 CEST
RedHat has issued an advisory for this in April 6:
https://access.redhat.com/errata/RHSA-2021:1086
Comment 5 David Walser 2021-05-30 21:23:31 CEST
openSUSE has issued an advisory for this on March 16:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IJZAIJRIBNKFP5CET6TYMJ3FGMU6WYAM/
Comment 6 David Walser 2021-06-09 15:28:06 CEST
RedHat has issued an advisory for this on June 8:
https://access.redhat.com/errata/RHSA-2021:2323
David Walser 2022-02-04 16:31:04 CET

Depends on: (none) => 30001

Comment 7 David Walser 2022-03-15 18:26:15 CET
(In reply to Nicolas Lécureuil from comment #3)
> mga7 and 8 and current cauldron are not affected, the code faulty code have
> been added later ( see https://github.com/389ds/389-ds-base/issues/2535 )

Oh thanks, closing this.

Status: NEW => RESOLVED
Resolution: (none) => INVALID