Bug 31878

Summary: connman new security issue CVE-2023-28488
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: andrewsfarm, davidwhodgins, geiger.david68210, herman.viaene, sysadmin-bugs
Version: 8Keywords: advisory, validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA8-64-OK
Source RPM: connman-1.38-2.3.mga8.src.rpm CVE:
Status comment:

Description David Walser 2023-05-06 22:31:43 CEST
Debian-LTS has issued an advisory on April 21:
https://www.debian.org/lts/security/2023/dla-3397

Mageia 8 is also affected.
David Walser 2023-05-06 22:31:54 CEST

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Patches available from upstream and Debian

Comment 1 David GEIGER 2023-05-07 09:33:14 CEST
Done for both mga8 and cauldron!

CC: (none) => geiger.david68210

Comment 2 David Walser 2023-05-07 19:35:19 CEST
connman-1.38-2.4.mga8
connman-devel-1.38-2.4.mga8

from connman-1.38-2.4.mga8.src.rpm

Status comment: Patches available from upstream and Debian => (none)
Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)
Source RPM: connman-1.41-1.mga9.src.rpm => connman-1.38-2.3.mga8.src.rpm
Assignee: bugsquad => qa-bugs

Comment 3 Herman Viaene 2023-05-16 12:38:07 CEST
MGA8-64 MATE on Acer Aspire 5253
No installation issues.
Followed commands from bug 30698 and bug 28321 with the same result i.e. the commands seem to go OK till the final connect, failng after entering the correct passphrase.
Let it go as TJ did in bug 306898.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA8-64-OK

Comment 4 Thomas Andrews 2023-05-16 16:39:30 CEST
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2023-05-16 19:06:52 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 5 Mageia Robot 2023-05-16 21:19:10 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0167.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED