Bug 25958 - jss new security issue CVE-2019-14823
Summary: jss new security issue CVE-2019-14823
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-12-26 04:45 CET by David Walser
Modified: 2020-01-05 16:40 CET (History)
5 users (show)

See Also:
Source RPM: jss-4.5.2-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2019-12-26 04:45:37 CET
Fedora has issued an advisory on October 25:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/O53NXVKMF7PJCPMCJQHLMSYCUGDHGBVE/

The issue is fixed upstream in 4.6.2, already in Cauldron and referencing this CVE in the commit message without filing a bug!
Comment 1 David GEIGER 2019-12-28 14:39:03 CET
Done for mga7!
Comment 2 David Walser 2019-12-28 18:23:37 CET
Advisory:
========================

Updated jss packages fix security vulnerability:

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS'
CryptoManager, where it implicitly trusted the root certificate of a
certificate chain. Applications using this policy may not properly verify the
chain and could be vulnerable to attacks such as Man in the Middle
(CVE-2019-14823).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14823
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/O53NXVKMF7PJCPMCJQHLMSYCUGDHGBVE/
========================

Updated packages in core/updates_testing:
========================
jss-4.6.2-1.mga7
jss-javadoc-4.6.2-1.mga7

from jss-4.6.2-1.mga7.src.rpm

Assignee: geiger.david68210 => qa-bugs
CC: (none) => geiger.david68210

Comment 3 Herman Viaene 2020-01-02 16:05:43 CET
MGA7-64 Plasma on Lenovo B50
No installation issues
Tried to find a usefull test
# urpmq --whatrequires jss
idm-console-framework
jss
jss-javadoc
ldapjdk

so installed idm-console-framework, but any jar I tried like:
java -jar   /usr/share/java/idm-console-mcc.jar
gives
no main manifest attribute, in /usr/share/java/idm-console-mcc.jar

Giving up, java stuff to OK on clean install?

CC: (none) => herman.viaene

Comment 4 David Walser 2020-01-02 16:29:42 CET
Clean upgrade is sufficient.
Herman Viaene 2020-01-02 16:30:20 CET

Whiteboard: (none) => MGA7-64-OK

Comment 5 Thomas Andrews 2020-01-03 19:05:43 CET
Validating. Advisory in Comment 2.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Thomas Backlund 2020-01-05 12:23:48 CET

CC: (none) => tmb
Keywords: (none) => advisory

Comment 6 Mageia Robot 2020-01-05 16:40:11 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0018.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.