Bug 665494

Summary: CVE-2008-5298 CVE-2008-5299 chm2pdf various flaws [fedora-all]
Product: [Fedora] Fedora Reporter: Vincent Danen <vdanen>
Component: chm2pdfAssignee: Narasimhan <lakshminaras2002>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: low Docs Contact:
Priority: low    
Version: 14CC: mail
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Release Note
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-02-07 17:03:39 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 474455, 474457    

Description Vincent Danen 2010-12-24 03:23:49 UTC
This is an automatically created tracking bug!  It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.

For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.

For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs

When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.

Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=474455

Please note: this issue affects multiple supported versions of Fedora.
Only one tracking bug has been filed; please only close it when all
affected versions are fixed.


[bug automatically created by: add-tracking-bugs]

Comment 1 Vincent Danen 2010-12-24 03:24:05 UTC
    Adding parent bug CVE-2008-5299
    New bodhi update url:
    https://admin.fedoraproject.org/updates/new/?type_=security&bugs=474455,474457

Comment 2 Fedora Admin XMLRPC Client 2010-12-30 02:50:28 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.

Comment 3 Narasimhan 2011-01-30 05:55:16 UTC
Submitted updates to Fedora 13 and Fedora 14 to fix the bugs.

https://admin.fedoraproject.org/updates/chm2pdf?_csrf_token=404fa2b41b44376674c8bd52d793ac1e825194d5

Comment 4 Narasimhan 2011-02-06 05:38:43 UTC
Can this defect (and blocking defects) be closed?

Comment 5 Vincent Danen 2011-02-07 17:03:39 UTC
Yes, thank you.  Not sure why it wasn't closed automatically.

This flaw was corrected in Fedora 14:

chm2pdf-0.9.1-9.fc14 (FEDORA-2011-0454)

and Fedora 13:

chm2pdf-0.9.1-8.fc13 (FEDORA-2011-0467)