Bug 742655

Summary: CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [epel-all]
Product: [Fedora] Fedora EPEL Reporter: Vincent Danen <vdanen>
Component: puppetAssignee: Jeroen van Meeuwen <vanmeeuwen+fedora>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: high    
Version: el6CC: k.georgiou, ktdreyer, pbrobinson, tmz, vanmeeuwen+fedora
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: 2.6.12-1.el6 2.6.12-1.el5 Doc Type: Release Note
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-11-29 14:34:43 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 742174, 742644, 742645, 742649    

Description Vincent Danen 2011-09-30 23:35:48 UTC
This is an automatically created tracking bug!  It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.

For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.

For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs

When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.

Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=742644

Please note: this issue affects multiple supported versions of Fedora EPEL.
Only one tracking bug has been filed; please only close it when all
affected versions are fixed.


[bug automatically created by: add-tracking-bugs]

Comment 1 Vincent Danen 2011-09-30 23:36:18 UTC
    Adding parent bug CVE-2011-3869
    New bodhi update url:
    https://admin.fedoraproject.org/updates/new/?type_=security&bugs=742644,742645

Comment 2 Vincent Danen 2011-09-30 23:36:48 UTC
    Adding parent bug CVE-2011-3871
    New bodhi update url:
    https://admin.fedoraproject.org/updates/new/?type_=security&bugs=742644,742645,742649

Comment 3 Vincent Danen 2011-09-30 23:37:20 UTC
    Adding parent bug CVE-2011-3848
    New bodhi update url:
    https://admin.fedoraproject.org/updates/new/?type_=security&bugs=742644,742645,742649,742174

Comment 4 Todd Zullinger 2011-10-01 00:07:49 UTC
Since updates were already submitted to bodhi (and in the case of EPEL, pushed to testing), what's the preferred method forward here (for both Fedora and EPEL)?

Comment 6 Vincent Danen 2011-10-04 19:54:24 UTC
If the bugs are linked, then bodhi should close the tracking bugs once they're pushed to stable.  I don't see any bugs linked, so that may not be the case.  When the bugs get pushed to stable, if these trackers aren't closed automatically, feel free to close them.

Thanks.

Comment 7 Todd Zullinger 2011-10-04 22:17:03 UTC
Will do.  There aren't any links because the updates were pushed before these tracker bugs were created¹. :)

¹ Other than for EL-4, which I neglected to take care of until yesterday.  Poor old EL-4.

Comment 8 Peter Robinson 2011-11-29 14:34:43 UTC
This has been fixed in EPEL 5 and 6 with build 2.6.12-1