Bug 30634

Summary: perl-HTTP-Daemon new security issue CVE-2022-31081
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: andrewsfarm, bruno, davidwhodgins, herman.viaene, marja11, sysadmin-bugs
Version: 8Keywords: advisory, validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA8-64-OK
Source RPM: perl-HTTP-Daemon-6.140.0-2.mga9.src.rpm CVE:
Status comment:

Description David Walser 2022-07-14 19:11:13 CEST
Ubuntu has issued an advisory today (July 14):
https://ubuntu.com/security/notices/USN-5520-1

The issue is fixed upstream in 6.15:
https://github.com/libwww-perl/HTTP-Daemon/security/advisories/GHSA-cg8c-pxmv-w7cf

Mageia 8 is also affected.
David Walser 2022-07-14 19:11:27 CEST

Status comment: (none) => Fixed upstream in 6.15
Whiteboard: (none) => MGA8TOO

Comment 1 Marja Van Waes 2022-07-16 11:35:41 CEST
Assigning to our Perl stack maintainers

Assignee: bugsquad => perl
CC: (none) => marja11

Comment 2 David Walser 2022-08-23 18:27:26 CEST
openSUSE has issued an advisory for this today (August 23):
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MZECADIWJOUORYOQTG5UI5M2TBA2O3BF/
Comment 3 Bruno Cornec 2022-09-07 00:31:30 CEST
https://cpan.metacpan.org/modules/by-module/HTTP/ doesn't propose 6.15, just 6.14 for now.

Status: NEW => ASSIGNED
CC: (none) => bruno

Comment 5 Bruno Cornec 2022-09-07 00:48:26 CEST
Pushed to updates_testing for mga8

Assignee: perl => qa-bugs

Bruno Cornec 2022-09-07 00:48:43 CEST

Version: Cauldron => 8

Bruno Cornec 2022-09-07 00:48:50 CEST

Whiteboard: MGA8TOO => (none)

Comment 6 David Walser 2022-09-07 01:19:18 CEST
perl-HTTP-Daemon-6.140-3.mga8

Status comment: Fixed upstream in 6.15 => (none)

Comment 7 Herman Viaene 2022-09-26 10:58:44 CEST
perl-HTTP-Daemon-6.140-3.mga8 not found in the remote repository

CC: (none) => herman.viaene

Comment 9 Herman Viaene 2022-09-27 16:35:03 CEST
OK, got it now
MGA8-64 MATE on Acer Aspire 5253
No installation issues.
No previous updates or wiki, so tried
# urpmq --whatrequires perl-HTTP-Daemon-6.140.0-3.mga8
fusioninventory-agent
perl-Frontier-RPC
perl-HTTP-Daemon
perl-HTTP-Daemon-SSL
perl-HTTP-Proxy
perl-Pod-POM-Web
perl-Test-HTTP-LocalServer
perl-libwww-perl
Had a short look at fusioninventory-agent, this is part of managing nodes in a cluster, way beyond me. The rest and the comment in MCC of packagee itself reads as a developer tool.
So proposing OK on clean install as it apprently does not disturb anything else.

Whiteboard: (none) => MGA8-64-OK

Comment 10 Thomas Andrews 2022-09-28 04:53:48 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2022-10-01 16:56:14 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 11 Mageia Robot 2022-10-01 19:49:57 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0349.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED