Bug 23445 - ldb new security issue CVE-2018-1140
Summary: ldb new security issue CVE-2018-1140
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Bruno Cornec
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-08-14 23:21 CEST by David Walser
Modified: 2018-10-27 17:16 CEST (History)
5 users (show)

See Also:
Source RPM: ldb-1.3.2-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2018-08-14 23:21:09 CEST
Samba has issued an advisory today (August 14):
https://www.samba.org/samba/security/CVE-2018-1140.html

The issue is fixed upstream in 1.3.5 and 1.4.1.
Comment 1 Marja Van Waes 2018-08-16 12:29:14 CEST
Assigning to all packagers collectively, since there is no registered maintainer for this package.

CC'ing some committers.

Assignee: bugsquad => pkg-bugs
CC: (none) => bgmilne, mageia, mageia, marja11

Comment 2 Bruno Cornec 2018-10-26 03:02:43 CEST
ldb-1.3.5-1.mga7 uploaded in cauldron

Resolution: (none) => FIXED
Status: NEW => RESOLVED
CC: (none) => bruno

Comment 3 David Walser 2018-10-26 03:05:00 CEST
As the comment in the SPEC file says, samba and sssd need to be rebuilt when this package is updated.

Status: RESOLVED => REOPENED
Resolution: FIXED => (none)

Comment 4 David Walser 2018-10-27 14:33:10 CEST
I see you've updated samba to 4.9.1 (thanks) which takes care of that one.  sssd should *not* be updated to 2.0.0.  1.13.x is the current LTM branch, and the 2.0.0 release notes say that 1.16.x might become one, so we should stay on one of those branches.
Comment 5 Bruno Cornec 2018-10-27 16:22:39 CEST
uploaded the following packages:
tdb-1.3.16-1.mga7
talloc-2.1.14-1.mga7
ldb-1.4.2-1.mga7
samba-4.9.1-1.mga7
sssd-1.13.4-16.mga7
Comment 6 Bruno Cornec 2018-10-27 16:23:26 CEST
I kept sssd 1.13 ;-)

Assignee: pkg-bugs => qa-bugs
Status: REOPENED => ASSIGNED

David Walser 2018-10-27 17:16:33 CEST

Assignee: qa-bugs => bruno

Comment 7 David Walser 2018-10-27 17:16:57 CEST
Perfect.

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.