Bug 25959 - koji new security issue CVE-2019-17109
Summary: koji new security issue CVE-2019-17109
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-12-26 04:48 CET by David Walser
Modified: 2021-03-21 11:45 CET (History)
2 users (show)

See Also:
Source RPM: koji-1.17.0-2.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2019-12-26 04:48:22 CET
Fedora has issued an advisory on October 25:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/7PSCCFHLNVFLDPC7DB4UJGXD6ZWBSY57/

The issue is fixed upstream in 1.18.1.

Mageia 7 is also affected.
David Walser 2019-12-26 04:48:32 CET

Whiteboard: (none) => MGA7TOO

David Walser 2020-01-14 17:38:33 CET

Status comment: (none) => Fixed upstream in 1.18.1

Comment 1 David Walser 2020-12-28 20:35:46 CET
koji-1.23.0-1.mga8 uploaded for Cauldron by Neal.

Whiteboard: MGA7TOO => (none)
Version: Cauldron => 7

Comment 2 Neal Gompa 2021-03-14 15:34:23 CET
I've uploaded a fixed version to updates-testing for Mageia 7.

Suggested advisory:
========================

Updated koji packages fix security vulnerabilities:

Koji through 1.17.0 allows remote Directory Traversal, with resultant Privilege Escalation.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17109
https://bugzilla.redhat.com/show_bug.cgi?id=1768882
========================

Updated packages in core/updates_testing:
========================
koji-1.17.1-1.mga7
python3-koji-1.17.1-1.mga7
python3-koji-cli-plugins-1.17.1-1.mga7
koji-hub-1.17.1-1.mga7
koji-hub-plugins-1.17.1-1.mga7
koji-builder-1.17.1-1.mga7
koji-vm-1.17.1-1.mga7
koji-utils-1.17.1-1.mga7
koji-web-1.17.1-1.mga7


Source RPMs: 
koji-1.17.1-1.mga7.src.rpm

Assignee: ngompa13 => qa-bugs
Status comment: Fixed upstream in 1.18.1 => Fixed upstream in 1.17.1

David Walser 2021-03-14 15:59:48 CET

Status comment: Fixed upstream in 1.17.1 => (none)

Comment 3 Thomas Andrews 2021-03-17 21:18:44 CET
Searched Bugzilla for previous updates, and found Bug 24421, where koji had been OKed and validated based on a clean install over the old packages.

I went to install all of the packages on a real hardware test install, but discovered that the total install, including dependencies, would involve 128 packages. Not wanting all those extra packages left after the test, I switched to a VirtualBox mga7-64 Plasma guest.

No installation issues when installing the current mga7 koji and dependencies, and all packages listed in Comment 2 updated cleanly.

Sending this one on its way. Validating. Advisory in Comment 2.

Keywords: (none) => validated_update
Whiteboard: (none) => MGA7-64-OK
CC: (none) => andrewsfarm, sysadmin-bugs

Thomas Backlund 2021-03-21 10:43:09 CET

Keywords: (none) => advisory

Comment 4 Mageia Robot 2021-03-21 11:45:29 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0147.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.