Bug 23312 - ceph new security issues CVE-2018-10861, CVE-2018-112[89], CVE-2018-14662, CVE-2018-16846, CVE-2018-16889
Summary: ceph new security issues CVE-2018-10861, CVE-2018-112[89], CVE-2018-14662, CV...
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Nicolas Lécureuil
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: 22774
  Show dependency treegraph
 
Reported: 2018-07-16 21:03 CEST by David Walser
Modified: 2019-11-06 13:33 CET (History)
2 users (show)

See Also:
Source RPM: ceph-10.2.9-1.mga7.src.rpm
CVE:
Status comment: Fixed upstream in 12.2.11


Attachments

Description David Walser 2018-07-16 21:03:19 CEST
SUSE has issued an advisory on July 10:
http://lists.suse.com/pipermail/sle-security-updates/2018-July/004254.html

It looks like they updated to a 12.2.5 git snapshot.

The security issues for this package are really piling up (also Bug 22774, Bug 21975, and Bug 22202).  Please fix them ASAP.
David Walser 2018-07-16 21:03:48 CEST

CC: (none) => jani.valimaa
Blocks: (none) => 22774

Comment 1 David Walser 2018-07-19 16:11:18 CEST
Fedora has issued an advisory for this on July 18:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/EF2VYLAB5Z7RYJI6BLWZXCWV5NZX323Q/

They've updated to 12.2.6.

Status comment: (none) => Fixed upstream in 12.2.6

Comment 2 David Walser 2018-11-14 23:53:48 CET
Debian has issued an advisory for this on November 13:
https://www.debian.org/security/2018/dsa-4339
Comment 3 Jani Välimaa 2018-11-20 19:11:25 CET
Ceph was dropped from Cauldron in September 2018.

http://svnweb.mageia.org/packages?view=revision&revision=1305047
http://svnweb.mageia.org/packages?view=revision&revision=1305049
Comment 4 David Walser 2018-11-21 00:38:43 CET
Thanks!  It's still in mga6 unfortunately.

Version: Cauldron => 6

Comment 5 David Walser 2019-02-20 23:09:37 CET
Fedora has issued an advisory today (February 20):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/PA6IXGMFUYQ5DC7VFR5LZFDAYIU4KEXR/

It fixes three new issues by updating to 12.2.11.

Summary: ceph new security issues CVE-2018-10861 and CVE-2018-112[89] => ceph new security issues CVE-2018-10861, CVE-2018-112[89], CVE-2018-14662, CVE-2018-16846, CVE-2018-16889
Status comment: Fixed upstream in 12.2.6 => Fixed upstream in 12.2.11

Comment 6 David Walser 2019-08-11 23:10:40 CEST
Ubuntu has issued an advisory for this on June 25:
https://usn.ubuntu.com/4035-1/
Comment 7 Mike Rambo 2019-11-06 13:33:18 CET
Mageia 6 is EOL.

Status: NEW => RESOLVED
Resolution: (none) => OLD
CC: (none) => mrambo


Note You need to log in before you can comment on or make changes to this bug.