| Summary: | Update mga9 to sympa 6.2.72 to fix CVE-2021-32850 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Bruno Cornec <bruno> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, dan, sysadmin-bugs |
| Version: | 9 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA9-64-OK | ||
| Source RPM: | sympa-6.2.70-1.mga9.src.rpm | CVE: | CVE-2021-32850 |
| Status comment: | |||
|
Description
Bruno Cornec
2024-02-26 11:23:02 CET
sympa-6.2.72-1.mga9.src.rpm provided in updates_testing with the generated packages: RPMS/x86_64/sympa-6.2.72-1.mga9.x86_64.rpm RPMS/x86_64/sympa-postgresql-6.2.72-1.mga9.x86_64.rpm RPMS/x86_64/sympa-www-6.2.72-1.mga9.x86_64.rpm RPMS/x86_64/sympa-mysql-6.2.72-1.mga9.x86_64.rpm I've run that in production on MGA8 for more than 6 months now and I'm updating my prod server to mga9 thus this update ! Status:
NEW =>
ASSIGNED
katnatek
2024-02-26 21:09:35 CET
Component:
RPM Packages =>
Security
katnatek
2024-02-26 21:15:36 CET
CC:
(none) =>
andrewsfarm
katnatek
2024-02-26 21:15:46 CET
Keywords:
(none) =>
advisory MGA9 Plasma in VirtualBox. Installed the current packages and dependencies, then updated using qarepo. No installation issues. The last two updates to sympa, bug 23536 and bug 26308, were OKed on the basis of a clean install, even though the tester was unable to get it running. As written in bug 23536 comment 10, "Sympa web interface may be quite difficult to setup for someone not familiar with configuring a web server manually." So, taking comment 1 as confirmation that this version works in Mageia 8, QA efforts mostly need to confirm that the update has that clean install in Mageia 9. So, giving this an OK, and validating. Bruno, if there are any issues with this in Mageia 9, it will be up to you to identify them and open another bug if necessary. Whiteboard:
(none) =>
MGA9-64-OK (In reply to Thomas Andrews from comment #2) > So, giving this an OK, and validating. Bruno, if there are any issues with > this in Mageia 9, it will be up to you to identify them and open another bug > if necessary. Thanks, that's fine with me. I think it's worthwhile mentioning in the release advisory that running "sympa upgrade" manually will be necessary for this update. Probably every Sympa sysadmin already knows this, but not all do. CC:
(none) =>
dan (In reply to Dan Fandrich from comment #4) > I think it's worthwhile mentioning in the release advisory that running > "sympa upgrade" manually will be necessary for this update. Probably every > Sympa sysadmin already knows this, but not all do. Not in the advisory, but perhaps in a README.install.urpmi file? What you think Bruno? Keywords:
validated_update =>
feedback Yes it should be in the advisory. A README.update.urpmi (not install) is a good idea too. (In reply to katnatek from comment #5) > (In reply to Dan Fandrich from comment #4) > > I think it's worthwhile mentioning in the release advisory that running > > "sympa upgrade" manually will be necessary for this update. Probably every > > Sympa sysadmin already knows this, but not all do. > > Not in the advisory, but perhaps in a README.install.urpmi file? > What you think Bruno? Yes would be a good idea. BTW I don't know why it's not recommended on https://wiki.mageia.org/en/Construire_des_paquetages_RPM-fr sympa-6.2.72-4 is now on its way for both cauldron and mga9 with this addition. (In reply to Bruno Cornec from comment #7) > (In reply to katnatek from comment #5) > > (In reply to Dan Fandrich from comment #4) > > > I think it's worthwhile mentioning in the release advisory that running > > > "sympa upgrade" manually will be necessary for this update. Probably every > > > Sympa sysadmin already knows this, but not all do. > > > > Not in the advisory, but perhaps in a README.install.urpmi file? > > What you think Bruno? > > Yes would be a good idea. > BTW I don't know why it's not recommended on > https://wiki.mageia.org/en/Construire_des_paquetages_RPM-fr https://wiki.mageia.org/en/Construire_des_paquetages_RPM-fr#Interaction_avec_urpmi_et_rpmdrake > > sympa-6.2.72-4 is now on its way for both cauldron and mga9 with this > addition. Thank you Real Hardware Mageia 8 x86_64 Basic test of update from current version See the warning about sympa upgrade Advisory Updated Validating again Keywords:
feedback =>
validated_update (In reply to katnatek from comment #9) > Real Hardware Mageia 8 x86_64 Of course, I mean Mageia 9 :facepalm: An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0052.html Resolution:
(none) =>
FIXED |