| Summary: | perl-HTTP-Daemon new security issue CVE-2022-31081 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, bruno, davidwhodgins, herman.viaene, marja11, sysadmin-bugs |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | perl-HTTP-Daemon-6.140.0-2.mga9.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2022-07-14 19:11:13 CEST
David Walser
2022-07-14 19:11:27 CEST
Status comment:
(none) =>
Fixed upstream in 6.15 Assigning to our Perl stack maintainers Assignee:
bugsquad =>
perl openSUSE has issued an advisory for this today (August 23): https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MZECADIWJOUORYOQTG5UI5M2TBA2O3BF/ https://cpan.metacpan.org/modules/by-module/HTTP/ doesn't propose 6.15, just 6.14 for now. Status:
NEW =>
ASSIGNED I think these 3 patches are needed: https://github.com/libwww-perl/HTTP-Daemon/commit/331d5c1d1f0e48e6b57ef738c2a8509b1eb53376.patch https://github.com/libwww-perl/HTTP-Daemon/commit/e84475de51d6fd7b29354a997413472a99db70b2.patch https://github.com/libwww-perl/HTTP-Daemon/commit/8dc5269d59e2d5d9eb1647d82c449ccd880f7fd0.patch From https://github.com/libwww-perl/HTTP-Daemon/issues/56 Pushed to cauldron. Pushed to updates_testing for mga8 Assignee:
perl =>
qa-bugs
Bruno Cornec
2022-09-07 00:48:43 CEST
Version:
Cauldron =>
8
Bruno Cornec
2022-09-07 00:48:50 CEST
Whiteboard:
MGA8TOO =>
(none) perl-HTTP-Daemon-6.140-3.mga8 Status comment:
Fixed upstream in 6.15 =>
(none) perl-HTTP-Daemon-6.140-3.mga8 not found in the remote repository CC:
(none) =>
herman.viaene OK, got it now MGA8-64 MATE on Acer Aspire 5253 No installation issues. No previous updates or wiki, so tried # urpmq --whatrequires perl-HTTP-Daemon-6.140.0-3.mga8 fusioninventory-agent perl-Frontier-RPC perl-HTTP-Daemon perl-HTTP-Daemon-SSL perl-HTTP-Proxy perl-Pod-POM-Web perl-Test-HTTP-LocalServer perl-libwww-perl Had a short look at fusioninventory-agent, this is part of managing nodes in a cluster, way beyond me. The rest and the comment in MCC of packagee itself reads as a developer tool. So proposing OK on clean install as it apprently does not disturb anything else. Whiteboard:
(none) =>
MGA8-64-OK Validating. Keywords:
(none) =>
validated_update
Dave Hodgins
2022-10-01 16:56:14 CEST
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2022-0349.html Resolution:
(none) =>
FIXED |