Bug 21786 - egroupware new security issue CVE-2017-14920
Summary: egroupware new security issue CVE-2017-14920
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Nicolas Lécureuil
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-09-29 21:26 CEST by David Walser
Modified: 2018-01-13 14:48 CET (History)
2 users (show)

See Also:
Source RPM: egroupware-1.8.007.20140506-8.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2017-09-29 21:26:06 CEST
A CVE has been assigned for a security issue fixed upstream in egroupware:
http://openwall.com/lists/oss-security/2017/09/29/12
http://openwall.com/lists/oss-security/2017/09/28/12

The message above contains a link to the commit that fixed the issue, which was also fixed in the 16.1.20170922 release.

Mageia 5 and Mageia 6 are also affected.

This package has been unmaintained in Mageia for a few years and should probably be dropped in Cauldron.
David Walser 2017-09-29 21:26:16 CEST

Whiteboard: (none) => MGA6TOO, MGA5TOO

Comment 1 Marja Van Waes 2017-09-30 05:47:29 CEST
(In reply to David Walser from comment #0)
> A CVE has been assigned for a security issue fixed upstream in egroupware:
> http://openwall.com/lists/oss-security/2017/09/29/12
> http://openwall.com/lists/oss-security/2017/09/28/12
> 
> The message above contains a link to the commit that fixed the issue, which
> was also fixed in the 16.1.20170922 release.
> 
> Mageia 5 and Mageia 6 are also affected.
> 
> This package has been unmaintained in Mageia for a few years and should
> probably be dropped in Cauldron.

Assigning to the registered maintainer.

Assignee: bugsquad => mageia
CC: (none) => marja11

Comment 2 David Walser 2017-12-29 18:45:14 CET
Upstream patch doesn't apply as-is.  I won't be fixing this for Mageia 5.

Package dropped from Cauldron.  Leaving open for Mageia 6 just in case someone ever wants to update this.

Whiteboard: MGA6TOO, MGA5TOO => (none)
Version: Cauldron => 6

Comment 3 Mike Rambo 2018-01-13 14:48:15 CET
Upstream patch does not apply. Three of the four files being patched do not exist in 1.8.007.20140506, and while the fourth file is there, the patch does not apply. The changes in that fourth section reference a variable which does not appear anywhere else in the source tree.

The patch, and perhaps this CVE, appears invalid for this version.

CC: (none) => mrambo
Resolution: (none) => INVALID
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.