Bug 983917 (CVE-2013-4116)
Summary: | CVE-2013-4116 npm: Insecure temporary directory generation | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | drieden, nobody+bgollahe, tchollingsworth, thrcka |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2014-02-23 16:00:09 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 983918, 983919, 983930 | ||
Bug Blocks: |
Description
Jan Lieskovsky
2013-07-12 09:34:15 UTC
This issue affects the versions of the npm package, as shipped with Fedora release of 18 and 19. Please schedule an update. -- This issue affects the versions of the npm package, as shipped with Fedora EPEL-6. Please schedule an update. Created npm tracking bugs for this issue: Affects: fedora-all [bug 983918] Affects: epel-6 [bug 983919] This is now fixed in Fedora 18, 19, and EPEL 6 stable repositories. Leaving this open since it still blocks a private bug. (In reply to T.C. Hollingsworth from comment #5) > This is now fixed in Fedora 18, 19, and EPEL 6 stable repositories. > > Leaving this open since it still blocks a private bug. Thank you, T.C. To leave this open was correct (the other npm package issue case shipped within Red Hat is in progress still). We will close this bug once the flaw has been corrected in all affected package versions. Regards, Jan. -- Jan iankko Lieskovsky / Red Hat Security Response Team Private bug has status "CLOSED ERRATA". Therefore I am closing this bug. Please re-open if required. |