Bug 29340

Summary: avahi new security issue CVE-2021-36217
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Nicolas Salguero <nicolas.salguero>
Status: RESOLVED DUPLICATE QA Contact: Sec team <security>
Severity: major    
Priority: Normal    
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA8TOO
Source RPM: avahi-0.8-8.mga9.src.rpm CVE:
Status comment: Patch available from Fedora and upstream

Description David Walser 2021-08-07 20:33:12 CEST
Fedora has issued an advisory today (August 7):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/7ZZUWPAGCR4VTIIRZB7PGOHUF5J6YQE5/

Mageia 8 is also affected.
David Walser 2021-08-07 20:34:00 CEST

Status comment: (none) => Patch available from Fedora and upstream
Whiteboard: (none) => MGA8TOO
CC: (none) => nicolas.salguero

Comment 1 Lewis Smith 2021-08-08 19:22:32 CEST
Historically different people have committed this SRPM, but NicolasS looks the best candidate to assign this to, so doing that in lieu of CC.

CC: nicolas.salguero => (none)
Assignee: bugsquad => nicolas.salguero

Comment 2 Nicolas Salguero 2021-08-30 12:05:29 CEST
According to https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36217, that CVE is a duplicate of CVE-2021-3502, which is already fixed.
Comment 3 David Walser 2021-08-30 16:04:19 CEST
RedHat marked it as duplicate now too.

*** This bug has been marked as a duplicate of bug 29239 ***

Resolution: (none) => DUPLICATE
Status: NEW => RESOLVED