Bug 14720 - apache-mod_wsgi new security issue CVE-2014-8583
Summary: apache-mod_wsgi new security issue CVE-2014-8583
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/624315/
Whiteboard: has_procedure mga4-32-ok MGA4-64-OK a...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2014-12-03 19:29 CET by David Walser
Modified: 2014-12-05 18:00 CET (History)
2 users (show)

See Also:
Source RPM: apache-mod_wsgi-3.5-1.1.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2014-12-03 19:29:05 CET
Ubuntu has issued an advisory today (December 3):
http://www.ubuntu.com/usn/usn-2431-1/

Cauldron is not affected as it was fixed upstream in 4.2.4 (we have 4.2.6).

Patched package uploaded for Mageia 4.

You can find information about testing this in our previous update, Bug 13831.

Advisory:
========================

Updated apache-mod_wsgi package fixes security vulnerability:

It was discovered that mod_wsgi incorrectly handled errors when setting up
the working directory and group access rights. A malicious application
could possibly use this issue to cause a local privilege escalation when
using daemon mode (CVE-2014-8583).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8583
http://www.ubuntu.com/usn/usn-2431-1/
========================

Updated packages in core/updates_testing:
========================
apache-mod_wsgi-3.5-1.2.mga4

from apache-mod_wsgi-3.5-1.2.mga4.src.rpm

Reproducible: 

Steps to Reproduce:
Comment 1 olivier charles 2014-12-03 22:09:06 CET
Testing on Mageia4x64 

Following procedure mentionned in Description (which contains 2 examples)

Current package :
-------------------- 
apache-mod_wsgi-3.5-1.1.mga4.x86_64

The 2 WSGI applications worked well

Updated testing package :
-----------------------
apache-mod_wsgi-3.5-1.2.mga4.x86_64

Restarted httpd service

Both WSGI applications ran as expected.

CC: (none) => olchal
Whiteboard: (none) => MGA4-64-OK

Comment 2 claire robinson 2014-12-05 16:33:53 CET
Testing complete mga4 32 with helloworld from
https://bugs.mageia.org/show_bug.cgi?id=13831#c6

Whiteboard: MGA4-64-OK => has_procedure mga4-32-ok MGA4-64-OK

Comment 3 Rémi Verschelde 2014-12-05 16:55:37 CET
Validating, advisory uploaded.

Please push to core/updates.

Keywords: (none) => validated_update
Whiteboard: has_procedure mga4-32-ok MGA4-64-OK => has_procedure mga4-32-ok MGA4-64-OK advisory
CC: (none) => sysadmin-bugs

Comment 4 Mageia Robot 2014-12-05 18:00:00 CET
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2014-0513.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.