Bug 22085 - spring-ldap new security issue CVE-2017-8028
Summary: spring-ldap new security issue CVE-2017-8028
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA6-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2017-11-26 19:24 CET by David Walser
Modified: 2018-05-16 10:26 CEST (History)
3 users (show)

See Also:
Source RPM: spring-ldap-1.3.1-14.mga6.src.rpm
CVE:
Status comment: Patch available from Debian


Attachments

Description David Walser 2017-11-26 19:24:22 CET
Debian has issued an advisory on November 22:
https://www.debian.org/security/2017/dsa-4046

Mageia 6 is also affected.
David Walser 2017-11-26 19:24:34 CET

CC: (none) => geiger.david68210
Whiteboard: (none) => MGA6TOO

David Walser 2018-02-02 18:23:12 CET

Status comment: (none) => Patch available from Debian

Comment 1 Mike Rambo 2018-04-29 02:10:23 CEST
Updated package uploaded for cauldron and Mageia 6.

Advisory:
========================

Updated spring-ldap package fixes security vulnerability:

It was discovered that spring-ldap would under some circumstances allow authentication with a correct username but an arbitrary password (CVE-2017-8028).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8028
https://www.debian.org/security/2017/dsa-4046
========================

Updated packages in core/updates_testing:
========================
spring-ldap-1.3.1-14.1.mga6.noarch.rpm
spring-ldap-javadoc-1.3.1-14.1.mga6.noarch.rpm

from spring-ldap-1.3.1-14.1.mga6.src.rpm

Assignee: mageia => qa-bugs
CC: (none) => mrambo
Version: Cauldron => 6
Whiteboard: MGA6TOO => (none)

Comment 2 Lewis Smith 2018-05-14 16:45:27 CEST
Testing M6/64

These packages have no previous updates.
Summary     : Java library for simplifying LDAP operations
Description :
Spring LDAP is a Java library for simplifying LDAP operations, based on the
pattern of Spring's JdbcTemplate. The framework relieves the user of common
chores, such as looking up and closing contexts, looping through results,
 etc etc etc

$ urpmq --whatrequires-recursive spring-ldap | sort -u
springframework-security
spring-ldap
-----------
Fortunately no sign of a test case (POC). Going for clean update only. Installing from issued repos:

# urpmi spring-ldap spring-ldap-javadoc
I fodloni dibyniaethau, gosodir y pecynnau canlynol:
  Pecyn                          Fersiwn      Rhifyn        Arch    
(cyfrwng "Core Release2")
  aopalliance                    1.0          15.mga6       noarch  
  apache-commons-io              2.4          11.mga6       noarch  
  apache-commons-lang            2.6          20.mga6       noarch  
  bea-stax-api                   1.2.0        13.mga6       noarch  
  bytelist                       1.0.8        12.mga6       noarch  
  cglib                          3.2.4        2.mga6        noarch  
  freemarker                     2.3.23       3.mga6        noarch  
  geronimo-interceptor           1.0.1        16.mga6       noarch  
  geronimo-validation            1.1          16.mga6       noarch  
  hibernate-jpa-2.0-api          1.0.1        19.mga6       noarch  
  hsqldb1                        1.8.1.3      11.mga6       noarch  
  jboss-connector-1.7-api        1.0.0        6.mga6        noarch  
  jcodings                       1.0.9        11.mga6       noarch  
  jettison                       1.3.7        3.mga6        noarch  
  log4j                          2.5          8.mga6        noarch  
  spring-ldap                    1.3.1        14.mga6       noarch  
  spring-ldap-javadoc            1.3.1        14.mga6       noarch  
  springframework                3.2.18       1.mga6        noarch  
  springframework-aop            3.2.18       1.mga6        noarch  
  springframework-batch          2.2.7        3.mga6        noarch  
  springframework-beans          3.2.18       1.mga6        noarch  
  springframework-context        3.2.18       1.mga6        noarch  
  springframework-expression     3.2.18       1.mga6        noarch  
  springframework-jdbc           3.2.18       1.mga6        noarch  
  springframework-retry          1.1.1        4.mga6        noarch  
  springframework-test           3.2.18       1.mga6        noarch  
  springframework-tx             3.2.18       1.mga6        noarch  

The UPDATE pulled in an updated library:
- liblog4j12-java-1.2.17-17.mga6.noarch
- spring-ldap-1.3.1-14.1.mga6.noarch
- spring-ldap-javadoc-1.3.1-14.1.mga6.noarch
and went without issue. Doubt we can do more. OKing etc the update.

Keywords: (none) => advisory, validated_update
Whiteboard: (none) => MGA6-64-OK
CC: (none) => sysadmin-bugs

Comment 3 Mageia Robot 2018-05-16 10:26:15 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2018-0235.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.