Bug 23171 - ppp possible new security issue CVE-2018-11574
Summary: ppp possible new security issue CVE-2018-11574
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-06-12 12:31 CEST by David Walser
Modified: 2019-01-21 03:15 CET (History)
1 user (show)

See Also:
Source RPM: ppp-2.4.7-9.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2018-06-12 12:31:06 CEST
A security issue in ppp has been announced:
http://openwall.com/lists/oss-security/2018/06/11/1

I don't know if we have the EAP-TLS patch.
Comment 1 Marja Van Waes 2018-06-12 13:44:34 CEST
Assigning to all pkgrs coll., since there is no registered maintainer for this pkg

Assignee: bugsquad => pkg-bugs
CC: (none) => marja11

Comment 2 David Walser 2018-06-21 00:18:31 CEST
Fedora has issued an advisory for this today (June 20):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/VIUYBKLQPV7ZLB6GDCQ6TLYUAAMT2RQI/
Comment 3 David Walser 2018-11-08 18:16:32 CET
Ubuntu has issued an advisory for this on November 6:
https://usn.ubuntu.com/3810-1/
Comment 4 David Walser 2019-01-21 03:15:44 CET
We don't appear to have the patch.

Status: NEW => RESOLVED
Resolution: (none) => INVALID


Note You need to log in before you can comment on or make changes to this bug.