Bug 26629 - python-beaker new security issue due to deserialization of untrusted data CVE-2013-7489
Summary: python-beaker new security issue due to deserialization of untrusted data CVE...
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Philippe Makowski
QA Contact: Sec team
URL:
Whiteboard: MGA8TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2020-05-15 20:16 CEST by David Walser
Modified: 2023-04-18 14:35 CEST (History)
2 users (show)

See Also:
Source RPM: python-beaker-1.11.0-3.mga8.src.rpm
CVE:
Status comment: No fix available as of end of 2020


Attachments

Description David Walser 2020-05-15 20:16:04 CEST
A security issue in python-beaker has been reported:
https://www.openwall.com/lists/oss-security/2020/05/14/11

There is no fix available yet.

Mageia 7 is also affected.
David Walser 2020-05-15 20:16:17 CEST

Status comment: (none) => No fix available as of May 2020
Whiteboard: (none) => MGA7TOO

Comment 1 Lewis Smith 2020-05-15 20:37:17 CEST
Leaving this with bugsquad until a fix materialises.

CC: (none) => lewyssmith

Comment 2 Aurelien Oudelet 2020-08-26 16:21:02 CEST
Hi
Here issue is closed with a merge:
https://github.com/bbangert/beaker/issues/35

Whereas this is still open:
https://github.com/bbangert/beaker/issues/191

There is a CVE here:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7489

Assigning to registered packager.

Assignee: bugsquad => makowski.mageia

Aurelien Oudelet 2020-08-26 16:21:40 CEST

Summary: python-beaker new security issue due to deserialization of untrusted data => python-beaker new security issue due to deserialization of untrusted data CVE-2013-7489

David Walser 2020-12-28 17:10:05 CET

Whiteboard: MGA7TOO => MGA8TOO, MGA7TOO

David Walser 2020-12-29 00:22:05 CET

Status comment: No fix available as of May 2020 => No fix available as of end of 2020

Comment 3 David Walser 2021-07-01 18:45:57 CEST
Removing Mageia 7 from whiteboard due to EOL:
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Whiteboard: MGA8TOO, MGA7TOO => MGA8TOO

Comment 4 Stig-Ørjan Smelror 2023-04-18 14:35:32 CEST
Package has been updated to version 1.12.1 in Cauldron.
No mention in the changelog about the security issues afaics.

CC: (none) => smelror


Note You need to log in before you can comment on or make changes to this bug.