Bug 22457 - curl new security issue CVE-2018-1000007
Summary: curl new security issue CVE-2018-1000007
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Shlomi Fish
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on: 22445 22772
Blocks:
  Show dependency treegraph
 
Reported: 2018-01-26 04:37 CET by David Walser
Modified: 2018-10-06 12:53 CEST (History)
1 user (show)

See Also:
Source RPM: curl-7.40.0-3.14.mga5.src.rpm
CVE:
Status comment: Fix checked into SVN


Attachments

Description David Walser 2018-01-26 04:37:07 CET
+++ This bug was initially created as a clone of Bug #22445 +++

Upstream has issued advisories today (January 24):
https://curl.haxx.se/docs/adv_2018-824a.html
https://curl.haxx.se/docs/adv_2018-b3bf.html

The issues are fixed in 7.58.0 (uploaded for Cauldron) and patches are available.

Mageia 5 has yet to be dealt with.  The patches don't apply cleanly as-is.

Flags: (none) => in_errata7-

Comment 1 Marja Van Waes 2018-01-26 07:35:04 CET
Assigning to the registered maintainer.



@ David

I don't understand why you set: 

    Flags: (none) => in_errata7-

Assignee: bugsquad => shlomif
CC: (none) => marja11

Comment 2 David Walser 2018-01-26 07:45:26 CET
I didn't, it did that when I cloned the other bug.  I tried to remove it.  It didn't work.

Flags: in_errata7- => (none)

Comment 3 David Walser 2018-01-28 19:01:56 CET
Debian has issued an advisory for this on January 26:
https://www.debian.org/security/2018/dsa-4098

CVE-2018-1000005 does not affect Mageia 5.

Rediffed patch from Debian checked into Mageia 5 SVN for CVE-2018-1000007.

Summary: curl new security issues CVE-2018-1000005 and CVE-2018-1000007 => curl new security issue CVE-2018-1000007

David Walser 2018-02-02 18:11:27 CET

Status comment: (none) => Fix checked into SVN

David Walser 2018-05-16 13:58:42 CEST

Depends on: (none) => 22772

Comment 4 David Walser 2018-09-05 13:51:03 CEST
Upstream has issued an advisory today (September 5):
https://curl.haxx.se/docs/CVE-2018-14618.html
Comment 5 Marja Van Waes 2018-10-06 12:53:34 CEST
The limited support Mga5 continued to have after its official EOL has ended, so closing this bug as OLD.

Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.