Bug 742655 - CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [epel-all]
Summary: CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws ...
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: puppet
Version: el6
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Jeroen van Meeuwen
QA Contact: Fedora Extras Quality Assurance
Depends On:
Blocks: CVE-2011-3848 CVE-2011-3870 CVE-2011-3869 CVE-2011-3871
TreeView+ depends on / blocked
Reported: 2011-09-30 23:35 UTC by Vincent Danen
Modified: 2011-11-29 14:34 UTC (History)
5 users (show)

Fixed In Version: 2.6.12-1.el6 2.6.12-1.el5
Doc Type: Release Note
Doc Text:
Clone Of:
Last Closed: 2011-11-29 14:34:43 UTC

Attachments (Terms of Use)

Description Vincent Danen 2011-09-30 23:35:48 UTC
This is an automatically created tracking bug!  It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora

For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.

For more information see:

When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.

Bodhi update submission link:

Please note: this issue affects multiple supported versions of Fedora EPEL.
Only one tracking bug has been filed; please only close it when all
affected versions are fixed.

[bug automatically created by: add-tracking-bugs]

Comment 1 Vincent Danen 2011-09-30 23:36:18 UTC
    Adding parent bug CVE-2011-3869
    New bodhi update url:

Comment 2 Vincent Danen 2011-09-30 23:36:48 UTC
    Adding parent bug CVE-2011-3871
    New bodhi update url:

Comment 3 Vincent Danen 2011-09-30 23:37:20 UTC
    Adding parent bug CVE-2011-3848
    New bodhi update url:

Comment 4 Todd Zullinger 2011-10-01 00:07:49 UTC
Since updates were already submitted to bodhi (and in the case of EPEL, pushed to testing), what's the preferred method forward here (for both Fedora and EPEL)?

Comment 6 Vincent Danen 2011-10-04 19:54:24 UTC
If the bugs are linked, then bodhi should close the tracking bugs once they're pushed to stable.  I don't see any bugs linked, so that may not be the case.  When the bugs get pushed to stable, if these trackers aren't closed automatically, feel free to close them.


Comment 7 Todd Zullinger 2011-10-04 22:17:03 UTC
Will do.  There aren't any links because the updates were pushed before these tracker bugs were created¹. :)

¹ Other than for EL-4, which I neglected to take care of until yesterday.  Poor old EL-4.

Comment 8 Peter Robinson 2011-11-29 14:34:43 UTC
This has been fixed in EPEL 5 and 6 with build 2.6.12-1

Note You need to log in before you can comment on or make changes to this bug.