Bug 1092091 (CVE-2014-2905, CVE-2014-2906, CVE-2014-2914, CVE-2014-3219)
Summary: | CVE-2014-2905 CVE-2014-2906 CVE-2014-2914 CVE-2014-3219 fish: multiple flaws fixed in upstream 2.1.1 | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Vincent Danen <vdanen> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | jaswinder, luto, oliver |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | fish 2.1.1 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2014-05-12 22:30:25 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1092092 | ||
Bug Blocks: |
Description
Vincent Danen
2014-04-28 17:54:48 UTC
Also, according to the Debian bug report [2] there is another symlink-based vulnerability for which a CVE has not yet been assigned, and for which a patch will be available shortly. [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746259#10 Created fish tracking bugs for this issue: Affects: fedora-all [bug 1092092] fish-2.1.0-9.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. (In reply to Vincent Danen from comment #1) > Also, according to the Debian bug report [2] there is another symlink-based > vulnerability for which a CVE has not yet been assigned, and for which a > patch will be available shortly. > > [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746259#10 This was assigned CVE-2014-3219: http://seclists.org/oss-sec/2014/q2/251 I believe that Fedora is now caught up with the appropriate Fish branch, and we have the fix for the change that was identified as relevant to CVE-2014-3219 on oss-sec, but I'm not really sure whether all known issues are fixed, so I'll leave this open until I get confirmation. Please don't steal SRT bugs. This bug is specifically for CVE-2014-3219 -- if there are other issues, they will get their own CVEs and will have bugs opened for them as appropriate. This has been fixed in Fedora 19 and 20 (thank you!) so it can now be closed. |