Bug 824082 (CVE-2011-2082, CVE-2011-2083, CVE-2011-2084, CVE-2011-2085, CVE-2011-4458, CVE-2011-4459, CVE-2011-4460)
Summary: | rt3: Multiple security flaws fixed in upstream v3.8.12 and v4.0.6 versions | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED UPSTREAM | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | alexmv, perl-devel, rc040203, tremble, xavier |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2019-06-10 10:58:36 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 824088, 824089 | ||
Bug Blocks: |
Description
Jan Lieskovsky
2012-05-22 17:11:14 UTC
These issues affect the versions of the rt3 package, as shipped with Fedora release of 15 and 16. Please schedule an update / rebase. -- These issues affect the versions of the rt3 package, as shipped with Fedora EPEL 5 and 6. Please schedule an update. Created rt3 tracking bugs for this issue Affects: fedora-all [bug 824088] Affects: epel-all [bug 824089] To anyone readying a release based on the above, please also note the two follow-up messages addressing problems with sending mail caused by the security patches: http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000205.html http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000206.html As the latter mentions, 3.8.13 should be released in the next couple days to address the issue with mod_perl deployments. - Alex Hmm, I am confused about http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000205.html There, you say: "RT 3.8.11 and 4.0.5 already require version (FCGI) 0.75 or higher". However, the latest version of FCGI.pm in CPAN is 0.74 as well as does rt-3.8.12/sbin/rt-test-dependencies check for FCGI 0.74? Could you elaborate? Gah -- simple typo. Please read that as 0.74, as you confirmed by looking at sbin/rt-test-dependencies.in - Alex Thanks for clarifying this. Fedora already ships 0.74, but ... CentOS6 is still at 0.71 ;) rt3-3.8.12-1.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report. rt3-3.8.12-1.fc15 has been pushed to the Fedora 15 stable repository. If problems still persist, please make note of it in this bug report. rt3-3.8.12-1.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report. This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products. |