Bug 837016 (CVE-2012-3818)
Summary: | CVE-2012-3818 revelation (fpm exporter): Password not encrypted when exporting a file | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | extras-orphan, jspaleta, pingou |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2015-08-22 16:16:08 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 837017, 837019 | ||
Bug Blocks: |
Description
Jan Lieskovsky
2012-07-02 14:14:35 UTC
This issue affects the versions of the revelation package, as shipped with Fedora release of 16 and 17. Please schedule an update once final upstream patch available. -- This issue affects the version of the revelation package, as shipped with Fedora EPEL 5. Please schedule an update once final upstream patch available. Created revelation tracking bugs for this issue Affects: fedora-all [bug 837017] Affects: epel-5 [bug 837019] Due the patch itself - upstream v0.14.4 release NEWS contains: 2012-07-01: Revelation 0.4.14 ============================= New features: - Added a new file encryption format using PBKDF2 #61 [Mikel Olasagasti Uranga] - Warn users about old file encryption format being non-secure - Moved applet to own dir to fix 'make dist' thus maybe adding a warning would be sufficient till there is upstream old-format fix. yes... pre-release scratch build has the patch..... rolling new scratch build and rawhide build with the new release today. -jef (In reply to comment #4) > rolling new scratch build and rawhide build with the new release today. Thanks for that, Jan. > > -jef |