Bug 31878 - connman new security issue CVE-2023-28488
Summary: connman new security issue CVE-2023-28488
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-05-06 22:31 CEST by David Walser
Modified: 2023-05-16 21:19 CEST (History)
5 users (show)

See Also:
Source RPM: connman-1.38-2.3.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2023-05-06 22:31:43 CEST
Debian-LTS has issued an advisory on April 21:
https://www.debian.org/lts/security/2023/dla-3397

Mageia 8 is also affected.
David Walser 2023-05-06 22:31:54 CEST

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Patches available from upstream and Debian

Comment 1 David GEIGER 2023-05-07 09:33:14 CEST
Done for both mga8 and cauldron!

CC: (none) => geiger.david68210

Comment 2 David Walser 2023-05-07 19:35:19 CEST
connman-1.38-2.4.mga8
connman-devel-1.38-2.4.mga8

from connman-1.38-2.4.mga8.src.rpm

Status comment: Patches available from upstream and Debian => (none)
Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)
Source RPM: connman-1.41-1.mga9.src.rpm => connman-1.38-2.3.mga8.src.rpm
Assignee: bugsquad => qa-bugs

Comment 3 Herman Viaene 2023-05-16 12:38:07 CEST
MGA8-64 MATE on Acer Aspire 5253
No installation issues.
Followed commands from bug 30698 and bug 28321 with the same result i.e. the commands seem to go OK till the final connect, failng after entering the correct passphrase.
Let it go as TJ did in bug 306898.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA8-64-OK

Comment 4 Thomas Andrews 2023-05-16 16:39:30 CEST
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2023-05-16 19:06:52 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 5 Mageia Robot 2023-05-16 21:19:10 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0167.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.