Bug 30634 - perl-HTTP-Daemon new security issue CVE-2022-31081
Summary: perl-HTTP-Daemon new security issue CVE-2022-31081
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-07-14 19:11 CEST by David Walser
Modified: 2022-10-01 19:49 CEST (History)
6 users (show)

See Also:
Source RPM: perl-HTTP-Daemon-6.140.0-2.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-07-14 19:11:13 CEST
Ubuntu has issued an advisory today (July 14):
https://ubuntu.com/security/notices/USN-5520-1

The issue is fixed upstream in 6.15:
https://github.com/libwww-perl/HTTP-Daemon/security/advisories/GHSA-cg8c-pxmv-w7cf

Mageia 8 is also affected.
David Walser 2022-07-14 19:11:27 CEST

Status comment: (none) => Fixed upstream in 6.15
Whiteboard: (none) => MGA8TOO

Comment 1 Marja Van Waes 2022-07-16 11:35:41 CEST
Assigning to our Perl stack maintainers

Assignee: bugsquad => perl
CC: (none) => marja11

Comment 2 David Walser 2022-08-23 18:27:26 CEST
openSUSE has issued an advisory for this today (August 23):
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MZECADIWJOUORYOQTG5UI5M2TBA2O3BF/
Comment 3 Bruno Cornec 2022-09-07 00:31:30 CEST
https://cpan.metacpan.org/modules/by-module/HTTP/ doesn't propose 6.15, just 6.14 for now.

Status: NEW => ASSIGNED
CC: (none) => bruno

Comment 5 Bruno Cornec 2022-09-07 00:48:26 CEST
Pushed to updates_testing for mga8

Assignee: perl => qa-bugs

Bruno Cornec 2022-09-07 00:48:43 CEST

Version: Cauldron => 8

Bruno Cornec 2022-09-07 00:48:50 CEST

Whiteboard: MGA8TOO => (none)

Comment 6 David Walser 2022-09-07 01:19:18 CEST
perl-HTTP-Daemon-6.140-3.mga8

Status comment: Fixed upstream in 6.15 => (none)

Comment 7 Herman Viaene 2022-09-26 10:58:44 CEST
perl-HTTP-Daemon-6.140-3.mga8 not found in the remote repository

CC: (none) => herman.viaene

Comment 9 Herman Viaene 2022-09-27 16:35:03 CEST
OK, got it now
MGA8-64 MATE on Acer Aspire 5253
No installation issues.
No previous updates or wiki, so tried
# urpmq --whatrequires perl-HTTP-Daemon-6.140.0-3.mga8
fusioninventory-agent
perl-Frontier-RPC
perl-HTTP-Daemon
perl-HTTP-Daemon-SSL
perl-HTTP-Proxy
perl-Pod-POM-Web
perl-Test-HTTP-LocalServer
perl-libwww-perl
Had a short look at fusioninventory-agent, this is part of managing nodes in a cluster, way beyond me. The rest and the comment in MCC of packagee itself reads as a developer tool.
So proposing OK on clean install as it apprently does not disturb anything else.

Whiteboard: (none) => MGA8-64-OK

Comment 10 Thomas Andrews 2022-09-28 04:53:48 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2022-10-01 16:56:14 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 11 Mageia Robot 2022-10-01 19:49:57 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0349.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.