Bug 30001 - 389-ds-base new security issue CVE-2021-45720
Summary: 389-ds-base new security issue CVE-2021-45720
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Nicolas Salguero
QA Contact: Sec team
URL:
Whiteboard: MGA8TOO
Keywords:
Depends on:
Blocks: 28536
  Show dependency treegraph
 
Reported: 2022-02-04 16:30 CET by David Walser
Modified: 2022-02-15 15:06 CET (History)
0 users

See Also:
Source RPM: 389-ds-base-1.4.0.26-10.mga9.src.rpm
CVE:
Status comment: Fixed upstream in 2.0.14


Attachments

Description David Walser 2022-02-04 16:30:43 CET
Fedora has issued an advisory today (February 4):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/Y7LTXE6LGBJI6YPVECO46TEBZ24UTPBA/

The issue is fixed upstream in 2.0.14.

Mageia 8 is also affected.
David Walser 2022-02-04 16:31:04 CET

Whiteboard: (none) => MGA8TOO
Blocks: (none) => 28536
Status comment: (none) => Fixed upstream in 2.0.14

Comment 1 Lewis Smith 2022-02-04 21:38:25 CET
Assigning to you, Nicolas, as you did a CVE patch for this thing not so long ago, so it is not unknown to you.

Assignee: bugsquad => nicolas.salguero

Comment 2 Nicolas Salguero 2022-02-15 13:54:56 CET
Hi,

That CVE is for Rust crate lru, which I did not find in 389-ds-base-1.4.0.26, so I think that CVE does not affect us.

Best regards,

Nico.
Comment 3 David Walser 2022-02-15 15:06:28 CET
OK, thanks.

Status: NEW => RESOLVED
Resolution: (none) => INVALID


Note You need to log in before you can comment on or make changes to this bug.