Bug 24494 - dnf-plugins-core new security issue CVE-2018-10897
Summary: dnf-plugins-core new security issue CVE-2018-10897
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: Neal Gompa
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-03-12 15:15 CET by David Walser
Modified: 2019-11-06 21:22 CET (History)
1 user (show)

See Also:
Source RPM: dnf-plugins-core-4.0.3-2.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2019-03-12 15:15:25 CET
Fedora has issued an advisory on February 21:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MKVE7N7VZH2T7GY65VZKWNNDACGZQRPQ/

The issue appears to be fixed upstream in 4.0.4.

Mageia 6 is also affected.

This issue is also in yum-utils, which is waiting for a packaging fix in Bug 23370.
David Walser 2019-03-12 15:15:36 CET

See Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=23370
Whiteboard: (none) => MGA6TOO

Comment 1 David Walser 2019-06-23 19:21:11 CEST
We have 4.0.7 in Cauldron.

Version: Cauldron => 6
Whiteboard: MGA6TOO => (none)

Comment 2 Mike Rambo 2019-11-06 21:22:56 CET
Mageia 6 is EOL.

Resolution: (none) => OLD
Status: NEW => RESOLVED
CC: (none) => mrambo


Note You need to log in before you can comment on or make changes to this bug.