Bug 23273 - accountsservice new security issue CVE-2018-14036
Summary: accountsservice new security issue CVE-2018-14036
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Shlomi Fish
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-07-03 14:04 CEST by David Walser
Modified: 2019-11-06 13:31 CET (History)
3 users (show)

See Also:
Source RPM: accountsservice-0.6.45-2.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2018-07-03 14:04:53 CEST
A security issue in accountsservice has been announced on July 2:
http://openwall.com/lists/oss-security/2018/07/02/2

The message above links to the upstream bug which contains a suggested patch.

Mageia 5 and Mageia 6 are also affected.
David Walser 2018-07-03 14:05:03 CEST

Whiteboard: (none) => MGA6TOO

Comment 1 Marja Van Waes 2018-07-04 12:34:22 CEST
Assigning to the registered maintainer.

Assignee: bugsquad => shlomif
CC: (none) => marja11

Comment 2 Shlomi Fish 2018-07-04 15:07:49 CEST
Fixed in mga7. Can anyone test there before i update mga6 too?

Version: Cauldron => 6
Whiteboard: MGA6TOO => (none)

Comment 3 Marja Van Waes 2018-07-06 14:51:52 CEST
(In reply to Shlomi Fish from comment #2)
> Fixed in mga7. Can anyone test there before i update mga6 too?

CC'ing all packagers collectively, maybe one of them can test. I can't test because I'm in too much in a hurry (need to travel to the LSM / RMML tonight). 

Is testing that it installs enough, or is there a PoC to test?

CC: (none) => pkg-bugs

Comment 4 David Walser 2018-07-21 20:39:30 CEST
A better fix than the suggested patch went upstream:
http://openwall.com/lists/oss-security/2018/07/20/4

Whiteboard: (none) => MGA6TOO
Version: 6 => Cauldron

Comment 5 David Walser 2018-11-08 18:51:49 CET
SUSE has issued an advisory for this on November 5:
http://lists.suse.com/pipermail/sle-security-updates/2018-November/004832.html

Summary: accountsservice new security issue => accountsservice new security issue CVE-2018-14036

Comment 6 David Walser 2018-11-15 00:33:07 CET
openSUSE has issued an advisory for this on November 10:
https://lists.opensuse.org/opensuse-updates/2018-11/msg00049.html
Comment 7 David Walser 2019-01-01 02:29:48 CET
Upstream fix included in 0.6.50.  I updated Cauldron to 0.6.54.

Version: Cauldron => 6
Whiteboard: MGA6TOO => (none)

Comment 8 Mike Rambo 2019-11-06 13:31:05 CET
Mageia 6 is EOL.

Resolution: (none) => OLD
Status: NEW => RESOLVED
CC: (none) => mrambo


Note You need to log in before you can comment on or make changes to this bug.