Bug 679339

Summary: CVE-2011-0432 pywebdav: SQL injection due improper escaping of user credentials [epel-5]
Product: [Fedora] Fedora EPEL Reporter: Huzaifa S. Sidhpurwala <huzaifas>
Component: pywebdavAssignee: Dan Horák <dan>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: medium    
Version: el5CC: dan, jtfas90
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: fst_owner=jtaylor
Fixed In Version: pywebdav-0.9.4.1-1.el5 Doc Type: Release Note
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-12-26 19:50:46 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 677718    

Description Huzaifa S. Sidhpurwala 2011-02-22 10:16:46 UTC
epel-5 tracking bug for pywebdav: see blocks bug list for full details of the security issue(s).

This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.


[bug automatically created by: add-tracking-bugs]

Comment 1 Jason Taylor 2014-12-09 13:05:52 UTC
Hi Dan,

Are there plans to upgrade the version of pywebdav in the epel el5 repo or should we look at retiring the package? Let me know if I can be of assistance.

Regards,

JT

Comment 2 Dan Horák 2014-12-09 17:25:25 UTC
uff, sounds I forgot about it, both Fedora and EL-6 were fixed on time

Comment 3 Fedora Update System 2014-12-10 14:49:10 UTC
pywebdav-0.9.4.1-1.el5 has been submitted as an update for Fedora EPEL 5.
https://admin.fedoraproject.org/updates/pywebdav-0.9.4.1-1.el5

Comment 4 Fedora Update System 2014-12-11 06:33:46 UTC
Package pywebdav-0.9.4.1-1.el5:
* should fix your issue,
* was pushed to the Fedora EPEL 5 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=epel-testing pywebdav-0.9.4.1-1.el5'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-4620/pywebdav-0.9.4.1-1.el5
then log in and leave karma (feedback).

Comment 5 Fedora Update System 2014-12-26 19:50:46 UTC
pywebdav-0.9.4.1-1.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.