Bug 23003 - derby new security issue CVE-2018-1313
Summary: derby new security issue CVE-2018-1313
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Java Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-05-08 16:04 CEST by David Walser
Modified: 2021-07-01 18:16 CEST (History)
2 users (show)

See Also:
Source RPM: derby-10.13.1.1-1.mga7.src.rpm
CVE: CVE-2018-1313
Status comment: Fixed upstream in 10.14.2.0


Attachments

Description David Walser 2018-05-08 16:04:02 CEST
Upstream has issued an advisory on May 5:
http://openwall.com/lists/oss-security/2018/05/05/1

The issue is fixed upstream in 10.14.2.0.

Mageia 5 and Mageia 6 are also affected.
David Walser 2018-05-08 16:04:09 CEST

Whiteboard: (none) => MGA6TOO

David Walser 2018-05-13 19:44:30 CEST

Status comment: (none) => Fixed upstream in 10.14.2.0

David Walser 2019-06-23 19:30:17 CEST

Whiteboard: MGA6TOO => MGA7TOO, MGA6TOO

Nicolas Lécureuil 2020-05-22 14:07:07 CEST

CC: (none) => mageia

Nicolas Lécureuil 2020-05-22 14:07:19 CEST

Whiteboard: MGA7TOO, MGA6TOO => MGA7TOO

Zombie Ryushu 2020-12-06 22:22:58 CET

CC: (none) => zombie_ryushu
CVE: (none) => CVE-2018-1313

Comment 1 David Walser 2020-12-27 18:15:52 CET
Appears to have been (mercifully) dropped from Cauldron.

Version: Cauldron => 7
Whiteboard: MGA7TOO => (none)

Comment 2 David Walser 2021-07-01 18:16:05 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.