Bug 20968 - systemd new security issue CVE-2017-9217
Summary: systemd new security issue CVE-2017-9217
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Colin Guthrie
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-05-29 14:25 CEST by David Walser
Modified: 2017-06-02 11:53 CEST (History)
2 users (show)

See Also:
Source RPM: systemd-230-10.mga6.src.rpm
CVE: CVE-2017-9217
Status comment:


Attachments

Description David Walser 2017-05-29 14:25:43 CEST
Fedora has issued an advisory on May 28:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/YXDUSK6OUHURC7O3QKNN3FUCEPB3SKIN/

The RedHat bug contains a link to the upstream commit that fixed the issue:
https://bugzilla.redhat.com/show_bug.cgi?id=1455493

Mageia 5 is also affected.
David Walser 2017-05-29 14:26:01 CEST

Whiteboard: (none) => MGA5TOO

Marja Van Waes 2017-05-29 20:56:41 CEST

CC: (none) => marja11
Assignee: bugsquad => mageia

Comment 1 Nicolas Lécureuil 2017-06-02 10:55:41 CEST
Fixed in cauldron

CVE: (none) => CVE-2017-9217
CC: (none) => mageia
Version: Cauldron => 5
Whiteboard: MGA5TOO => (none)

Comment 2 Nicolas Lécureuil 2017-06-02 10:59:48 CEST
there is no dns_packet_is_reply_for function in systemd 217 so mga5 is not affected ( please reopen if i am wrong )

Resolution: (none) => FIXED
Status: NEW => RESOLVED

Comment 3 David Walser 2017-06-02 11:53:40 CEST
Indeed, RedHat later posted that the issue was introduced in systemd 225.

Version: 5 => Cauldron


Note You need to log in before you can comment on or make changes to this bug.