Bug 22016 - glusterfs new security issue CVE-2017-15096
Summary: glusterfs new security issue CVE-2017-15096
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-11-12 20:00 CET by David Walser
Modified: 2017-11-20 11:57 CET (History)
3 users (show)

See Also:
Source RPM: glusterfs-3.7.9-1.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2017-11-12 20:00:51 CET
Fedora has issued an advisory on November 11:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/LM6ZNCU2KVKOL44GHTMMKKXJ4G5GHKYZ/

There has been some debate as to whether to classify this as a security issue.  We should at least include the fix in Cauldron and Mageia 6 SVN.  Fedora added a patch to fix it in this commit:
http://pkgs.fedoraproject.org/cgit/rpms/glusterfs.git/commit/?id=202c34e6826fd2cba34ee61fc14312126ede808f
Comment 1 Marja Van Waes 2017-11-12 22:26:41 CET
Assigning to all packagers collectively, since there is no registered maintainer for this package.

Assignee: bugsquad => pkg-bugs
CC: (none) => marja11

Comment 2 Marc Krämer 2017-11-20 00:08:32 CET
glusterfs is already in task-obsoletes (for mga6 and cauldron).

The question is, why python-gluster is still present in the repo and why task-obsoletes does not remove it.

CC: (none) => mageia

Comment 3 José Jorge 2017-11-20 11:47:47 CET
If python-gluster has no other dep, it is simply because of human error. It must be added to task-obsoletes and moved in the svn (not removed) according to this :

https://wiki.mageia.org/en/Packaging_guidelines#Obsoleting_a_package

You are welcome to do so.

CC: (none) => lists.jjorge

Comment 4 David Walser 2017-11-20 11:57:21 CET
Thanks Marc.  I thought we had dropped this package, so I guess I wasn't crazy after all.  It was typed incorrectly as python-glusterfs in task-obsolete, so it was still hanging around.  glusterfs actually isn't in SVN at all.

Status: NEW => RESOLVED
Resolution: (none) => INVALID


Note You need to log in before you can comment on or make changes to this bug.