Bug 875889
Summary: | CVE-2012-4417 GlusterFS: insecure temporary file creation [epel-all] | ||
---|---|---|---|
Product: | [Fedora] Fedora EPEL | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | glusterfs | Assignee: | Niels de Vos <ndevos> |
Status: | CLOSED UPSTREAM | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | el6 | CC: | joe, jonathansteffan, matthias, ndevos, silas |
Target Milestone: | --- | Keywords: | Security, SecurityTracking |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Release Note | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2013-10-27 11:57:26 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 856341 |
Description
Jan Lieskovsky
2012-11-12 18:36:42 UTC
Please use the following update submission link to create the Bodhi request for this issue as it contains the top-level parent bug(s) as well as this tracking bug. This will ensure that all associated bugs get updated when new packages are pushed to stable. Please also ensure that the "Close bugs when update is stable" option remains checked. Bodhi update submission link: https://admin.fedoraproject.org/updates/new/?type_=security&bugs=856341,875889 Upstream fixes (from Bug 856341): > commit 3d10587d9d6400c9141b1f278bb5e2027fa784b8 (http://review.gluster.org/4042) > and > commit 56d1f81949fde78615cd9fec048259d261f99c40 (http://review.gluster.org/4091) > > are done upstream to handle it. This will be fixed automatically with the update to GlusterFS 3.4. EPEL will not be updated to glusterfs-3.4 due to conflicts it will introduce in RHEL. The glusterfs package has been orphaned in EPEL now, the suggestion is to use the community packages from http://download.gluster.org/pub/gluster/glusterfs/LATEST/RHEL/. |