Please see Bug #1380464 - et seq, through Bug #1380468
c-ares was added to RHEL6 as documented in Bug #513673. The security fix referenced here (and version bump) was applied to EPEL5, EPEL7, and all Fedora versions, but not the standard c-ares package in RHEL6, as far as I can tell.
+++ This bug was initially created as a clone of Bug #1380466 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
--- Additional comment from Adam Mariš on 2016-09-29 12:32:16 EDT ---
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
# testing, stable
# Bug numbers: 1234,9876
# Description of your update
notes=Security fix for CVE-2016-5180
# Enable request automation based on the stable/unstable karma thresholds
# Automatically close bugs when this marked as stable
# Suggest that users restart after update
Additionally, you may opt to use the bodhi web interface to submit updates:
--- Additional comment from Fedora Update System on 2016-10-01 00:45:53 EDT ---
c-ares-1.12.0-1.el5 has been pushed to the Fedora EPEL 5 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-c9c041384d
--- Additional comment from Fedora Update System on 2016-10-20 06:18:00 EDT ---
c-ares-1.12.0-1.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.
Product Security rated this as having Moderate security impact and currently does not plan to address this issue in RHEL products. Note that impact of this issue on RHEL is less severe than impact on ChromeOS.
(In reply to Adam Mariš from comment #2)
> Product Security rated this as having Moderate security impact and currently
> does not plan to address this issue in RHEL products. Note that impact of
> this issue on RHEL is less severe than impact on ChromeOS.
While noted, this does lead to the strange result that it's fixed for EL5 and EL7 users, but not those on EL6.
Furthermore, mingw-c-ares was updated in EL6, but the main c-ares package wasn't. This could easily lead to confusion.
I understand the specific chain of reasoning for the EL6 package... But this is one of those cases where I'd ask that the team reconsider this, and either backport the patch or also perform the rebase here too.
I'm sorry, but given that RHEL-6 in in Production Phase 3 and given the reasoning in comment #2, I'm closing this bug as WONTFIX.
I understand the reasoning in comment #3, but I'm afraid we cannot fix bugs with this severity at this point of RHEL-6 lifecycle.