Bug 22253 - ruby-net-ldap new security issue CVE-2017-17718
Summary: ruby-net-ldap new security issue CVE-2017-17718
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Pascal Terjan
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-12-22 20:17 CET by David Walser
Modified: 2019-11-06 13:18 CET (History)
1 user (show)

See Also:
Source RPM: ruby-net-ldap-0.12.1-1.mga6.src.rpm
CVE:
Status comment: Fixed upstream in 0.16.0


Attachments

Description David Walser 2017-12-22 20:17:05 CET
A CVE has been assigned for a security issue in ruby-net-ldap:
http://openwall.com/lists/oss-security/2017/12/17/10

The issue was fixed upstream in 0.16.0 (already in Cauldron).

If I'm reading this correctly, it's not considered a security issue in versions before 0.10.0 (thus Mageia 5).
David Walser 2018-02-02 18:26:00 CET

Status comment: (none) => Fixed upstream in 0.16.0

Comment 1 Mike Rambo 2019-11-06 13:18:17 CET
Mageia 6 is EOL.

CC: (none) => mrambo
Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.