Bug 11701 - python-djblets new security issue CVE-2013-4519
Summary: python-djblets new security issue CVE-2013-4519
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: i586 Linux
Priority: Normal major
Target Milestone: ---
Assignee: Nicolas Lécureuil
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/574205/
Whiteboard:
Keywords:
Depends on:
Blocks: 11726
  Show dependency treegraph
 
Reported: 2013-11-18 22:05 CET by David Walser
Modified: 2014-01-09 16:10 CET (History)
1 user (show)

See Also:
Source RPM: python-djblets-0.7.21-5.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2013-11-18 22:05:05 CET
Fedora has issued an advisory on November 15:
https://lists.fedoraproject.org/pipermail/package-announce/2013-November/121923.html

The issue appears to be fixed upstream in 0.7.23.

Reproducible: 

Steps to Reproduce:
David Walser 2013-11-21 23:05:17 CET

Blocks: (none) => 11726

Comment 1 Shlomi Fish 2014-01-04 17:20:36 CET
Hi,

(In reply to David Walser from comment #0)
> Fedora has issued an advisory on November 15:
> https://lists.fedoraproject.org/pipermail/package-announce/2013-November/
> 121923.html
> 
> The issue appears to be fixed upstream in 0.7.23.
> 
> Reproducible: 
> 
> Steps to Reproduce:

I upgraded djblets to 0.7.28 here:

shlomif[rpms]:$mageia/python-djblets$ svn info
Path: .
Working Copy Root Path: /home/shlomif/Download/unpack/Mageia/python-djblets
URL: svn+ssh://svn.mageia.org/svn/packages/cauldron/python-djblets/current
Relative URL: ^/cauldron/python-djblets/current
Repository Root: svn+ssh://svn.mageia.org/svn/packages
Repository UUID: 01bf705a-734c-4999-978a-dc8ab10ec44d
Revision: 564597
Node Kind: directory
Schedule: normal
Last Changed Author: shlomif
Last Changed Rev: 564597
Last Changed Date: 2014-01-04 18:17:40 +0200 (Sat, 04 Jan 2014)

shlomif[rpms]:$mageia/python-djblets$ 

Shall I submit a freeze request? Does this need update in Mageia 3 as well?

-- Shlomif

CC: (none) => shlomif

Comment 2 David Walser 2014-01-04 17:31:43 CET
Yes and yes, please.  Thank you.
Comment 3 Shlomi Fish 2014-01-04 17:55:25 CET
(In reply to David Walser from comment #2)
> Yes and yes, please.  Thank you.

OK, I submitted a freeze request, but it seems that python-djblets does not exist in Mageia 3 (or in its updates) so I don't see a point submitting the package there.
Comment 4 David Walser 2014-01-04 22:20:42 CET
Ahh yes, this bug is only for Cauldron.  I was on my cell phone when I posted earlier so I missed that :o)  Thanks again.
Comment 5 David Walser 2014-01-09 16:10:13 CET
python-djblets-0.7.28-1.mga4 uploaded for Cauldron.

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.