Bug 22645 - suricata new security issues CVE-2018-6794, CVE-2018-1024[2-4], CVE-2018-18956
Summary: suricata new security issues CVE-2018-6794, CVE-2018-1024[2-4], CVE-2018-18956
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Guillaume Rousse
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-02-24 17:15 CET by David Walser
Modified: 2019-11-06 13:20 CET (History)
1 user (show)

See Also:
Source RPM: suricata-4.0.3-1.mga7.src.rpm
CVE:
Status comment: Fixed upstream in 4.0.6


Attachments

Description David Walser 2018-02-24 17:15:40 CET
Fedora has issued an advisory on February 23:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MMJ7GBVHN2GV3KAIBBRSZU2JQA5X4ZPO/

Mageia 6 is also affected.
Comment 1 David Walser 2018-02-24 17:18:21 CET
I don't know if upstream has a fix for 3.x.

Status comment: (none) => Fixed upstream in 4.0.4 and 4.1
Whiteboard: (none) => MGA6TOO

Comment 2 David Walser 2018-02-24 23:56:57 CET
suricata-4.0.4-1.mga7 uploaded for Cauldron by Guillaume.

Whiteboard: MGA6TOO => (none)
Version: Cauldron => 6

Comment 3 David Walser 2018-08-02 17:57:11 CEST
Fedora has issued an advisory on July 27:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/IMIFOK6VUND3RKJXVUFONSJWOW4XTZPP/

It fixes new security issues fixed upstream in 4.0.5.

Version: 6 => Cauldron
Summary: suricata new security issue CVE-2018-6794 => suricata new security issues CVE-2018-6794 and CVE-2018-1024[2-4]
Whiteboard: (none) => MGA6TOO
Status comment: Fixed upstream in 4.0.4 and 4.1 => Fixed upstream in 4.0.5 and 4.1

Comment 4 David Walser 2018-08-02 23:43:00 CEST
suricata-4.0.5-1.mga7 uploaded for Cauldron by Guillaume.

Version: Cauldron => 6
Whiteboard: MGA6TOO => (none)

Comment 5 David Walser 2018-11-20 23:49:21 CET
Fedora has issued an advisory on November 17:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/EYQZIRT47GKRBLGSLTHTT4KNRRPYBVHF/

It fixes one new security issue fixed upstream in 4.0.6.

Summary: suricata new security issues CVE-2018-6794 and CVE-2018-1024[2-4] => suricata new security issues CVE-2018-6794, CVE-2018-1024[2-4], CVE-2018-18956
Status comment: Fixed upstream in 4.0.5 and 4.1 => Fixed upstream in 4.0.6

Comment 6 Mike Rambo 2019-11-06 13:20:25 CET
Mageia 6 is EOL.

Resolution: (none) => OLD
Status: NEW => RESOLVED
CC: (none) => mrambo


Note You need to log in before you can comment on or make changes to this bug.